Skip to content

upstream-sync: v0.7.31 → stack tip (2026-08-06-3) - #687

Draft
utcarshsrivastava-collab wants to merge 17 commits into
upstream-sync/2026-08-06T10-38-40from
upstream-sync/2026-08-06T11-28-59
Draft

upstream-sync: v0.7.31 → stack tip (2026-08-06-3)#687
utcarshsrivastava-collab wants to merge 17 commits into
upstream-sync/2026-08-06T10-38-40from
upstream-sync/2026-08-06T11-28-59

Conversation

@utcarshsrivastava-collab

@utcarshsrivastava-collab utcarshsrivastava-collab commented Aug 6, 2026

Copy link
Copy Markdown
Collaborator

Upstream sync — 2026-08-06-3

Merges simstudioai/sim@e01bfb14 into upstream-sync/2026-08-06T10-38-40.

Sync range: 6 commit(s) since 207785c8 (lastSyncedUpstreamSha).

Stack

# Release PR Branch Status
1 unknown #681 upstream-sync/2026-08-05T10-46-19 open
2 v0.7.30 #685 upstream-sync/2026-08-06T10-38-40 open
3 v0.7.31 #687 ← tip upstream-sync/2026-08-06T11-28-59 open

Tip-only landing: merge the tip PR into the target branch, then close lower stack PRs as superseded.

Ledger

Verification

bun run check · ⚠️ bun run lint

Check / lint are advisory. Test and full build are left to CI.

Advisory verification failed (check/lint). These do not block the sync. bun run test and full bun run build are left to CI. Review and fix on the draft PR as needed.

bun run check

✅ passed

$ turbo run format:check

   • Packages in scope: @sim/audit, @sim/auth, @sim/db, @sim/emcn, @sim/logger, @sim/pii, @sim/platform-authz, @sim/realtime, @sim/realtime-protocol, @sim/runtime-secrets, @sim/security, @sim/testing, @sim/tsconfig, @sim/utils, @sim/workflow-persistence, @sim/workflow-renderer, @sim/workflow-types, docs, sim, simstudio, simstudio-ts-sdk
   • Running format:check in 21 packages
   • Remote caching disabled

::group::@sim/auth:format:check
cache miss, executing 7b95f933c974b740
$ biome format .
Checked 3 files in 11ms. No fixes applied.
::endgroup::
::group::simstudio:format:check
cache miss, executing db888607b0259b5e
$ biome format .
Checked 3 files in 22ms. No fixes applied.
::endgroup::
::group::@sim/logger:format:check
cache miss, executing d07801b30193037f
$ biome format .
Checked 6 files in 36ms. No fixes applied.
::endgroup::
::group::@sim/workflow-types:format:check
cache miss, executing d343ec897a7b120b
$ biome format .
Checked 4 files in 46ms. No fixes applied.
::endgroup::
::group::@sim/workflow-renderer:format:check
cache miss, executing 1549899c6299c617
$ biome format .
Checked 13 files in 84ms. No fixes applied.
::endgroup::
::group::@sim/security:format:check
cache miss, executing fc2410243714aad2
$ biome format .
Checked 13 files in 65ms. No fixes applied.
::endgroup::
::group::@sim/realtime:format:check
cache miss, executing 50312f9021db7fb0
$ biome format .
Checked 32 files in 308ms. No fixes applied.
::endgroup::
::group::@sim/testing:format:check
cache miss, executing 6754342b8949f5f1
$ biome format .
Checked 66 files in 353ms. No fixes applied.
::endgroup::
::group::@sim/platform-authz:format:check
cache miss, executing 20bfbd17ba902713
$ biome format .
Checked 5 files in 48ms. No fixes applied.
::endgroup::
::group::@sim/workflow-persistence:format:check
cache miss, executing 6a2f322f646254f4
$ biome format .
Checked 8 files in 65ms. No fixes applied.
::endgroup::
::group::simstudio-ts-sdk:format:check
cache miss, execu

bun run lint

❌ failed (advisory)

$ turbo run lint

   • Packages in scope: @sim/audit, @sim/auth, @sim/db, @sim/emcn, @sim/logger, @sim/pii, @sim/platform-authz, @sim/realtime, @sim/realtime-protocol, @sim/runtime-secrets, @sim/security, @sim/testing, @sim/tsconfig, @sim/utils, @sim/workflow-persistence, @sim/workflow-renderer, @sim/workflow-types, docs, sim, simstudio, simstudio-ts-sdk
   • Running lint in 21 packages
   • Remote caching disabled

::group::simstudio:lint
cache miss, executing 3b3448794fd8d67a
$ biome check --write --unsafe .
Checked 3 files in 31ms. No fixes applied.
::endgroup::
::group::@sim/logger:lint
cache miss, executing 101959f903fffb42
$ biome check --write --unsafe .
Checked 6 files in 65ms. No fixes applied.
::endgroup::
::group::@sim/realtime-protocol:lint
cache miss, executing 0122da9ed0cc036d
$ biome check --write --unsafe .
Checked 5 files in 93ms. No fixes applied.
::endgroup::
::group::@sim/security:lint
cache miss, executing f0d899d639617b3d
$ biome check --write --unsafe .
Checked 13 files in 105ms. No fixes applied.
::endgroup::
::group::@sim/workflow-types:lint
cache miss, executing c5a2ba3ebbfce6a3
$ biome check --write --unsafe .
Checked 4 files in 114ms. No fixes applied.
::endgroup::
::group::@sim/workflow-renderer:lint
cache miss, executing 766887a777f1bb1f
$ biome check --write --unsafe .
Checked 13 files in 166ms. No fixes applied.
::endgroup::
::group::simstudio-ts-sdk:lint
cache miss, executing c86521201f82f1d8
$ biome check --write --unsafe .
Checked 6 files in 196ms. No fixes applied.
::endgroup::
::group::@sim/runtime-secrets:lint
cache miss, executing 0affd3cfd3a3ca22
$ biome check --write --unsafe .
Checked 5 files in 40ms. No fixes applied.
::endgroup::
::group::@sim/utils:lint
cache miss, executing 07ed1635ff1bad02
$ biome check --write --unsafe .
Checked 22 files in 298ms. No fixes applied.
::endgroup::
::group::@sim/auth:lint
cache miss, executing 9430b4cb7b0f5ea1
$ biome check --write --unsafe .
Checked 3 files in 50ms. No fixes applied.
::endgroup::
::group::@sim/platform-authz:lint
cache miss, executing 5c043a9e7804d1fa
$ biome check --write --unsafe .
Checked 5 files in 81ms. No fixes applied.
::endgroup::
::group::@sim/workflow-persistence:lint
cache miss, executing a6585cd84bdc79fc
$ biome check --write --unsafe .
Checked 8 files in 88ms. No fixes applied.
::endgroup::
::group::@sim/audit:lint
cache miss, executing 176f393c5252970e
$ biome check --write --unsafe .
Checked 7 files in 136ms. No fixes applied.
::endgroup::
::group::@sim/testing:lint
cache miss, executing 3e85379ba14ee220
$ biome check --write --unsafe .
Checked 66 files in 674ms. No fixes applied.
::endgroup::
::group::@sim/realtime:lint
cache miss, executing ed2fe0202e342b01
$ biome check --write --unsafe .
Checked 32 files in 607ms. No fixes applied.
::endgroup::
::group::@sim/emcn:lint
cache miss, executing ac892d7173f5ca3a
$ biome check --write --unsafe .
Checked 189 files in 1480ms. No fixes applied.
::endgroup::
::group::docs:lint
cache miss, executing 3ca2b0f772ab34ad
$ biome check --write --unsafe .
Checked 101 files in 1309ms. No fixes applied.
::endgroup::
::group::@sim/db:lint
cache miss, executing 5be67c93d969bd53
$ biome check --write --unsafe .
Checked 284 files in 7s. No fixes applied.
::endgroup::
�[;31msim:lint�[;0m
cache miss, executing 95a6d6486881cba3
$ biome check --write --unsafe .
app/workspace/[workspaceId]/home/components/message-content/components/special-tags/choice-blocks.ts:56:7 lint/suspicious/noShadowRestrictedNames ━━━━━━━━━━

  × Do not shadow the global "escape" property.
  
    54 │   let depth = 0
    55 │   let inString = false
  > 56 │   let escape = false
       │       ^^^^^^
    57 │ 
    58 │   for (let i = startIdx; i < text.length; i++) {
  
  i Consider renaming this variable. It's easy to confuse the origin of variables when they're named after a known global.
  

Checked 11375 files in 34s. Fixed 8 files.
Found 1 error.
check ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

  × Some errors were emitted while running checks.
  

error: script "lint" exited with code 1
::error::sim#lint: command (/home/runner/work/p2-sim/p2-sim/apps/sim) /home/runner/.bun/bin/bun run lint exited (1)
 ERROR  sim#lint: command (/home/runner/work/p2-sim/p2-sim/apps/sim) /home/runner/.bun/bin/bun run lint exited (1)

 Tasks:    18 successful, 19 total
Cached:    0 cached, 19 total
  Time:    35.759s 
Failed:    sim#lint

 ERROR  run failed: command  exited (1)
error: script "lint" exited with code 1

Agent usage

Usage (stack rollup)

  • This slice: $2.9826 · 6,952,815 in / 49,507 out · 3 agent(s)
  • Prior stack: $8.0957 · 22,147,093 in / 170,237 out · 8 agent(s)
  • Whole stack: $11.0784 · 29,099,908 in / 219,744 out · 11 agent(s)

parent-grill-analysis

  • Model: claude-opus-5
  • Iterations: 1
  • Input tokens (direct): 59
  • Input tokens (cache read): 2,014,694
  • Input tokens (cache create): 71,388
  • Input tokens (total): 2,086,141
  • Output tokens: 22,776
  • Cost: $2.026137 (provider-reported)

parent-finalize-plan

  • Model: claude-opus-5
  • Iterations: 1
  • Input tokens (direct): 3,607
  • Input tokens (cache read): 523,621
  • Input tokens (cache create): 49,731
  • Input tokens (total): 576,959
  • Output tokens: 9,440
  • Cost: $0.829078 (provider-reported)

child-finalize-merge

  • Model: gpt-5.6-luna
  • Iterations: 1
  • Input tokens (direct): 116,028
  • Input tokens (cache read): 4,173,687
  • Input tokens (cache create): 0
  • Input tokens (total): 4,289,715
  • Output tokens: 17,291
  • Cost: $0.127429 (estimated fallback)

Totals

  • Total input tokens: 6,952,815
  • Total output tokens: 49,507
  • Primary models: claude-opus-5, gpt-5.6-luna
  • Total cost: $2.982644
  • Provider-reported cost: $2.855215
  • Estimated cost (fallback): $0.127429

Cost by agent

  • parent-grill-analysis: $2.026137 (provider-reported)
  • parent-finalize-plan: $0.829078 (provider-reported)
  • child-finalize-merge: $0.127429 (estimated fallback)

Draft — tip-only landing: merge this tip into the target branch, then close lower stack PRs as superseded.

waleedlatif1 and others added 16 commits July 11, 2026 21:31
…ioai#5618)

* feat(sidebar): add Cmd+B shortcut to toggle sidebar collapse

* fix(sidebar): skip Cmd+B sidebar toggle inside editable fields

* fix(sidebar): don't dead-zone Cmd+B on read-only editors; drop stale Mod+B ownership

* chore(lint): apply biome fixes
…scription creation (simstudioai#5619)

* fix(webhooks): resolve env var references before deploy-triggered subscription creation

Provider config fields like an API key can reference an environment
variable via {{VAR_NAME}}. The interactive trigger-save route already
resolved these before calling a provider's createSubscription, but the
async deployment-outbox path (workflow deploy -> saveTriggerWebhooksForDeploy
-> createExternalWebhookSubscription) did not, so the literal unresolved
{{VAR_NAME}} string was sent to the provider as the credential and
rejected. Resolve env vars in createExternalWebhookSubscription itself so
both callers behave the same; the persisted providerConfig keeps storing
the unresolved template, only the outbound call gets the resolved value.

* fix(webhooks): guard against a non-string workspaceId when resolving env vars

workflow.workspaceId as string | undefined was an unchecked cast on a
Record<string, unknown> — if a caller ever passed a workflow-like object
where workspaceId isn't actually a string, workspace-scoped {{VAR}}
references would silently stay unresolved and the provider would receive
the literal template as the credential, reproducing the exact class of bug
this change exists to fix. Replaced with a runtime typeof check that falls
back to undefined (personal-env-only resolution) instead of forwarding an
unvalidated value.
… before dispatch (simstudioai#5621)

* fix(ashby): parse alternateEmailAddresses and socialLinks into arrays before dispatch

The Ashby create_candidate and update_candidate tools require
alternateEmailAddresses (string[]) and socialLinks ({type,url}[]) as
JSON arrays in the request body, guarded by Array.isArray checks. The
block collected both through long-input text fields but forwarded the
raw string straight through to tools.config.params, so Array.isArray
was always false and both fields were silently dropped on every
create/update call.

Parse them in tools.config.params (execution-time, after variable
resolution) using the same comma-separated-or-JSON-array pattern used
elsewhere in the codebase (see blocks/findymail.ts), and add wandConfig
to both fields so the AI wand can generate well-formed input for them.

* fix(ashby): drop json-object generationType from array-shaped wandConfig fields

generationType: 'json-object' makes the wand API append an instruction
that the response must start with { and end with }, but
alternateEmailAddresses/socialLinks parse a raw JSON array or
comma-separated string, not an object. A wand-generated
{"emails":[...]}-shaped response would get comma-split into invalid
email fragments by parseStringListInput, and an object-wrapped
socialLinks response would get silently dropped by parseSocialLinksInput
returning []. Matches the existing array-field wandConfig pattern in
blocks/findymail.ts, which never sets generationType and relies on the
prompt text alone.

* fix(ashby): remove the non-functional candidateId filter from list_applications

Live-verified against Ashby's application.list endpoint: passing
candidateId (including a nonexistent UUID) returns identical, unfiltered
results either way — Ashby's API silently ignores this body field
entirely. Sending it gave users the false impression of filtering by
candidate while actually returning every application. Removed the param,
the tool type, and the block's filterCandidateId subBlock/wiring/input.
The correct path for a candidate's applications is ashby_get_candidate's
applicationIds field.

* fix(ashby): add subblock-id migration for the removed filterCandidateId field

The subblock ID stability CI check correctly caught that removing
filterCandidateId without a migration entry would silently drop the
value on already-deployed workflows. Added the standard _removed_ mapping,
following the same pattern already used for this block's prior removals
(emailType, phoneType, expandApplicationFormDefinition,
expandSurveyFormDefinitions).
…imstudioai#5623)

* fix(global-commands): use isContentEditable for the editable guard

* chore(lint): keep focusable span in editable-guard test with biome-ignore
…Links (simstudioai#5624)

* fix(ashby): fail loudly instead of silently dropping malformed socialLinks

parseSocialLinksInput returned [] for any non-JSON-parseable input, and
tools.config.params only sets result.socialLinks when the parsed array is
non-empty — so a malformed socialLinks string (user typo, or a wand
response that didn't follow the JSON-array prompt) silently omitted the
field entirely. The Ashby candidate.update call then succeeded without
applying the requested links, with no error surfaced to the workflow
author. Throw a clear error instead, matching the existing
throw-on-invalid-JSON pattern used elsewhere (e.g. blocks/airtable.ts).

* fix(ashby): use getErrorMessage instead of inline error-message extraction

check:utils bans the e instanceof Error ? e.message : fallback pattern in
favor of getErrorMessage(e, fallback?) from @sim/utils/errors.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants