Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,16 +2,16 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1949 / -925 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> took `pnpm-lock.yaml` to +318 / -737 and so to risk **67520**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> `overrides:` block in `pnpm-workspace.yaml` (risk 667) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

Expand DownExpand Up@@ -95,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `pnpm-lock.yaml` | +318/-737 | 64 | **67520** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-419 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -104,7 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `pnpm-workspace.yaml` | +23 | 29 | **667** | **Row 37, added 2026-08-08.** 13 major-scoped entries appended to upstream's existing `overrides:` block: brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, nanoid@3, path-to-regexp, shell-quote, tar, undici@6. These are the transitive advisories Dependabot cannot auto-fix — it only ever bumps a `package.json`. Together with the re-resolution pass they took the fork from **107 open alerts to 6**. Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand Down
14 changes: 4 additions & 10 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions pnpm-workspace.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -118,6 +118,11 @@ overrides:
"form-data@4": ^4.0.6
"hono@4": ^4.12.34
"ip-address@10": ^10.3.1
# Added 2026-08-08, one commit after the sweep: astro 7.2.0 brought in a fixed
# nanoid@3.3.17 but left the old 3.3.12 beside it, and the restructure flipped that
# copy's scope from development to runtime — which took GHSA #115/#116 out from under
# GitHub's auto-dismiss rule and reopened them. This dedupes the two copies onto 3.3.17.
"nanoid@3": ^3.3.17
"path-to-regexp@6": ^6.3.0
"shell-quote@1": ^1.9.0
"tar@7": ^7.5.21
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,16 +2,16 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1949 / -925 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> took `pnpm-lock.yaml` to +318 / -737 and so to risk **67520**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> `overrides:` block in `pnpm-workspace.yaml` (risk 667) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

Expand DownExpand Up@@ -95,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `pnpm-lock.yaml` | +318/-737 | 64 | **67520** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-419 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -104,7 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `pnpm-workspace.yaml` | +23 | 29 | **667** | **Row 37, added 2026-08-08.** 13 major-scoped entries appended to upstream's existing `overrides:` block: brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, nanoid@3, path-to-regexp, shell-quote, tar, undici@6. These are the transitive advisories Dependabot cannot auto-fix — it only ever bumps a `package.json`. Together with the re-resolution pass they took the fork from **107 open alerts to 6**. Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand Down
14 changes: 4 additions & 10 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions pnpm-workspace.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -118,6 +118,11 @@ overrides:
"form-data@4": ^4.0.6
"hono@4": ^4.12.34
"ip-address@10": ^10.3.1
# Added 2026-08-08, one commit after the sweep: astro 7.2.0 brought in a fixed
# nanoid@3.3.17 but left the old 3.3.12 beside it, and the restructure flipped that
# copy's scope from development to runtime — which took GHSA #115/#116 out from under
# GitHub's auto-dismiss rule and reopened them. This dedupes the two copies onto 3.3.17.
"nanoid@3": ^3.3.17
"path-to-regexp@6": ^6.3.0
"shell-quote@1": ^1.9.0
"tar@7": ^7.5.21
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,16 +2,16 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1949 / -925 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> took `pnpm-lock.yaml` to +318 / -737 and so to risk **67520**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> `overrides:` block in `pnpm-workspace.yaml` (risk 667) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

Expand DownExpand Up@@ -95,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `pnpm-lock.yaml` | +318/-737 | 64 | **67520** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-419 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -104,7 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `pnpm-workspace.yaml` | +23 | 29 | **667** | **Row 37, added 2026-08-08.** 13 major-scoped entries appended to upstream's existing `overrides:` block: brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, nanoid@3, path-to-regexp, shell-quote, tar, undici@6. These are the transitive advisories Dependabot cannot auto-fix — it only ever bumps a `package.json`. Together with the re-resolution pass they took the fork from **107 open alerts to 6**. Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand Down
14 changes: 4 additions & 10 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions pnpm-workspace.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -118,6 +118,11 @@ overrides:
"form-data@4": ^4.0.6
"hono@4": ^4.12.34
"ip-address@10": ^10.3.1
# Added 2026-08-08, one commit after the sweep: astro 7.2.0 brought in a fixed
# nanoid@3.3.17 but left the old 3.3.12 beside it, and the restructure flipped that
# copy's scope from development to runtime — which took GHSA #115/#116 out from under
# GitHub's auto-dismiss rule and reopened them. This dedupes the two copies onto 3.3.17.
"nanoid@3": ^3.3.17
"path-to-regexp@6": ^6.3.0
"shell-quote@1": ^1.9.0
"tar@7": ^7.5.21
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,16 +2,16 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1949 / -925 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> took `pnpm-lock.yaml` to +318 / -737 and so to risk **67520**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> `overrides:` block in `pnpm-workspace.yaml` (risk 667) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

Expand DownExpand Up@@ -95,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `pnpm-lock.yaml` | +318/-737 | 64 | **67520** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-419 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -104,7 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `pnpm-workspace.yaml` | +23 | 29 | **667** | **Row 37, added 2026-08-08.** 13 major-scoped entries appended to upstream's existing `overrides:` block: brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, nanoid@3, path-to-regexp, shell-quote, tar, undici@6. These are the transitive advisories Dependabot cannot auto-fix — it only ever bumps a `package.json`. Together with the re-resolution pass they took the fork from **107 open alerts to 6**. Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand Down
14 changes: 4 additions & 10 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions pnpm-workspace.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -118,6 +118,11 @@ overrides:
"form-data@4": ^4.0.6
"hono@4": ^4.12.34
"ip-address@10": ^10.3.1
# Added 2026-08-08, one commit after the sweep: astro 7.2.0 brought in a fixed
# nanoid@3.3.17 but left the old 3.3.12 beside it, and the restructure flipped that
# copy's scope from development to runtime — which took GHSA #115/#116 out from under
# GitHub's auto-dismiss rule and reopened them. This dedupes the two copies onto 3.3.17.
"nanoid@3": ^3.3.17
"path-to-regexp@6": ^6.3.0
"shell-quote@1": ^1.9.0
"tar@7": ^7.5.21
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,16 +2,16 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1949 / -925 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> took `pnpm-lock.yaml` to +318 / -737 and so to risk **67520**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> `overrides:` block in `pnpm-workspace.yaml` (risk 667) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

Expand DownExpand Up@@ -95,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `pnpm-lock.yaml` | +318/-737 | 64 | **67520** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-419 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -104,7 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `pnpm-workspace.yaml` | +23 | 29 | **667** | **Row 37, added 2026-08-08.** 13 major-scoped entries appended to upstream's existing `overrides:` block: brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, nanoid@3, path-to-regexp, shell-quote, tar, undici@6. These are the transitive advisories Dependabot cannot auto-fix — it only ever bumps a `package.json`. Together with the re-resolution pass they took the fork from **107 open alerts to 6**. Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand Down
14 changes: 4 additions & 10 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions pnpm-workspace.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -118,6 +118,11 @@ overrides:
"form-data@4": ^4.0.6
"hono@4": ^4.12.34
"ip-address@10": ^10.3.1
# Added 2026-08-08, one commit after the sweep: astro 7.2.0 brought in a fixed
# nanoid@3.3.17 but left the old 3.3.12 beside it, and the restructure flipped that
# copy's scope from development to runtime — which took GHSA #115/#116 out from under
# GitHub's auto-dismiss rule and reopened them. This dedupes the two copies onto 3.3.17.
"nanoid@3": ^3.3.17
"path-to-regexp@6": ^6.3.0
"shell-quote@1": ^1.9.0
"tar@7": ^7.5.21
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,16 +2,16 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1949 / -925 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> took `pnpm-lock.yaml` to +318 / -737 and so to risk **67520**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> `overrides:` block in `pnpm-workspace.yaml` (risk 667) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

Expand DownExpand Up@@ -95,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `pnpm-lock.yaml` | +318/-737 | 64 | **67520** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-419 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -104,7 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `pnpm-workspace.yaml` | +23 | 29 | **667** | **Row 37, added 2026-08-08.** 13 major-scoped entries appended to upstream's existing `overrides:` block: brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, nanoid@3, path-to-regexp, shell-quote, tar, undici@6. These are the transitive advisories Dependabot cannot auto-fix — it only ever bumps a `package.json`. Together with the re-resolution pass they took the fork from **107 open alerts to 6**. Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand Down
14 changes: 4 additions & 10 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions pnpm-workspace.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -118,6 +118,11 @@ overrides:
"form-data@4": ^4.0.6
"hono@4": ^4.12.34
"ip-address@10": ^10.3.1
# Added 2026-08-08, one commit after the sweep: astro 7.2.0 brought in a fixed
# nanoid@3.3.17 but left the old 3.3.12 beside it, and the restructure flipped that
# copy's scope from development to runtime — which took GHSA #115/#116 out from under
# GitHub's auto-dismiss rule and reopened them. This dedupes the two copies onto 3.3.17.
"nanoid@3": ^3.3.17
"path-to-regexp@6": ^6.3.0
"shell-quote@1": ^1.9.0
"tar@7": ^7.5.21
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,16 +2,16 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1949 / -925 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> took `pnpm-lock.yaml` to +318 / -737 and so to risk **67520**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> `overrides:` block in `pnpm-workspace.yaml` (risk 667) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

Expand DownExpand Up@@ -95,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `pnpm-lock.yaml` | +318/-737 | 64 | **67520** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-419 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -104,7 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `pnpm-workspace.yaml` | +23 | 29 | **667** | **Row 37, added 2026-08-08.** 13 major-scoped entries appended to upstream's existing `overrides:` block: brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, nanoid@3, path-to-regexp, shell-quote, tar, undici@6. These are the transitive advisories Dependabot cannot auto-fix — it only ever bumps a `package.json`. Together with the re-resolution pass they took the fork from **107 open alerts to 6**. Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand Down
14 changes: 4 additions & 10 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions pnpm-workspace.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -118,6 +118,11 @@ overrides:
"form-data@4": ^4.0.6
"hono@4": ^4.12.34
"ip-address@10": ^10.3.1
# Added 2026-08-08, one commit after the sweep: astro 7.2.0 brought in a fixed
# nanoid@3.3.17 but left the old 3.3.12 beside it, and the restructure flipped that
# copy's scope from development to runtime — which took GHSA #115/#116 out from under
# GitHub's auto-dismiss rule and reopened them. This dedupes the two copies onto 3.3.17.
"nanoid@3": ^3.3.17
"path-to-regexp@6": ^6.3.0
"shell-quote@1": ^1.9.0
"tar@7": ^7.5.21
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,16 +2,16 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1949 / -925 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> took `pnpm-lock.yaml` to +318 / -737 and so to risk **67520**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> `overrides:` block in `pnpm-workspace.yaml` (risk 667) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

Expand DownExpand Up@@ -95,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `pnpm-lock.yaml` | +318/-737 | 64 | **67520** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-419 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -104,7 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `pnpm-workspace.yaml` | +23 | 29 | **667** | **Row 37, added 2026-08-08.** 13 major-scoped entries appended to upstream's existing `overrides:` block: brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, nanoid@3, path-to-regexp, shell-quote, tar, undici@6. These are the transitive advisories Dependabot cannot auto-fix — it only ever bumps a `package.json`. Together with the re-resolution pass they took the fork from **107 open alerts to 6**. Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand Down
14 changes: 4 additions & 10 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions pnpm-workspace.yaml
Original file line numberDiff line numberDiff line change
Expand Up@@ -118,6 +118,11 @@ overrides:
"form-data@4": ^4.0.6
"hono@4": ^4.12.34
"ip-address@10": ^10.3.1
# Added 2026-08-08, one commit after the sweep: astro 7.2.0 brought in a fixed
# nanoid@3.3.17 but left the old 3.3.12 beside it, and the restructure flipped that
# copy's scope from development to runtime — which took GHSA #115/#116 out from under
# GitHub's auto-dismiss rule and reopened them. This dedupes the two copies onto 3.3.17.
"nanoid@3": ^3.3.17
"path-to-regexp@6": ^6.3.0
"shell-quote@1": ^1.9.0
"tar@7": ^7.5.21
Expand Down
Loading