fix: publish v5 local CI, context, and desktop safeguards - #53
RecursiveIntell wants to merge 12 commits into
Conversation
૮ >ﻌ< ა ci reviewran on 5e5bdff — fix(iso): sanitize compute-host marker in certify harness
|
| Package | Before | After |
|---|---|---|
| @electron/get | 2.0.3 |
5.1.0 |
| brace-expansion (nested under @eslint/config-array) | 1.1.12 |
1.1.18 |
| brace-expansion (nested under @eslint/eslintrc) | 1.1.12 |
1.1.18 |
| electron | 40.10.2 |
40.10.6 |
| brace-expansion (nested under eslint) | 1.1.12 |
1.1.18 |
| js-yaml | 4.3.1 |
4.3.2 |
| ➕ @electron-internal/extract-zip | — | 1.0.5 |
| ➕ env-paths (nested under @electron/get) | — | 3.0.0 |
| ➕ undici (nested under @electron/get) | — | 7.29.0 |
| ➖ semver (nested under @electron/get) | 6.3.1 |
— |
| ➖ @types/yauzl | 2.10.3 |
— |
| ➖ extract-zip | 2.0.1 |
— |
| ➖ fs-extra | 8.1.0 |
— |
| ➖ pend | 1.2.0 |
— |
| ➖ yauzl | 3.4.0 |
— |
scripts/whatsapp-bridge/package-lock.json
| Package | Before | After |
|---|---|---|
| @emnapi/runtime | 1.11.2 |
1.11.3 |
| @img/sharp-darwin-arm64 | 0.35.3 |
0.35.4 |
| @img/sharp-darwin-x64 | 0.35.3 |
0.35.4 |
| @img/sharp-freebsd-wasm32 | 0.35.3 |
0.35.4 |
| @img/sharp-libvips-darwin-arm64 | 1.3.2 |
1.3.3 |
| @img/sharp-libvips-darwin-x64 | 1.3.2 |
1.3.3 |
| @img/sharp-libvips-linux-arm | 1.3.2 |
1.3.3 |
| @img/sharp-libvips-linux-arm64 | 1.3.2 |
1.3.3 |
| @img/sharp-libvips-linux-ppc64 | 1.3.2 |
1.3.3 |
| @img/sharp-libvips-linux-riscv64 | 1.3.2 |
1.3.3 |
| @img/sharp-libvips-linux-s390x | 1.3.2 |
1.3.3 |
| @img/sharp-libvips-linux-x64 | 1.3.2 |
1.3.3 |
| @img/sharp-libvips-linuxmusl-arm64 | 1.3.2 |
1.3.3 |
| @img/sharp-libvips-linuxmusl-x64 | 1.3.2 |
1.3.3 |
| @img/sharp-linux-arm | 0.35.3 |
0.35.4 |
| @img/sharp-linux-arm64 | 0.35.3 |
0.35.4 |
| @img/sharp-linux-ppc64 | 0.35.3 |
0.35.4 |
| @img/sharp-linux-riscv64 | 0.35.3 |
0.35.4 |
| @img/sharp-linux-s390x | 0.35.3 |
0.35.4 |
| @img/sharp-linux-x64 | 0.35.3 |
0.35.4 |
| @img/sharp-linuxmusl-arm64 | 0.35.3 |
0.35.4 |
| @img/sharp-linuxmusl-x64 | 0.35.3 |
0.35.4 |
| @img/sharp-wasm32 | 0.35.3 |
0.35.4 |
| @img/sharp-webcontainers-wasm32 | 0.35.3 |
0.35.4 |
| @img/sharp-win32-arm64 | 0.35.3 |
0.35.4 |
| @img/sharp-win32-ia32 | 0.35.3 |
0.35.4 |
| @img/sharp-win32-x64 | 0.35.3 |
0.35.4 |
| qs | 6.15.3 |
6.16.0 |
| sharp | 0.35.3 |
0.35.4 |
website/package-lock.json
| Package | Before | After |
|---|---|---|
| baseline-browser-mapping | 2.10.43 |
2.11.20 |
| browserslist | 4.28.6 |
4.28.8 |
| caniuse-lite | 1.0.30001806 |
1.0.30001810 |
| colord | 2.9.3 |
2.9.4 |
| electron-to-chromium | 1.5.392 |
1.5.418 |
| fast-uri | 3.1.5 |
3.1.6 |
| joi | 17.13.4 |
17.13.6 |
| js-yaml | 4.3.1 |
4.3.2 |
| node-releases | 2.0.51 |
2.0.54 |
| qs | 6.15.3 |
6.16.0 |
| svgo | 3.3.4 |
3.3.5 |
| update-browserslist-db | 1.2.3 |
1.3.2 |
| ➕ nanoid | — | 3.3.18 |
| ➖ nanoid (nested under postcss) | 3.3.17 |
— |
How to fix:
Add the ci-reviewed label after verifying the version changes are expected.
⚠️ Warnings
OSV vulnerability scan · View job
7 known vulnerabilities found in pinned dependencies.
- CVE-2026-13149 in package-lock.json
- CVE-2026-84373 in package-lock.json
- CVE-2026-84373 in package-lock.json
- CVE-2026-70608 in package-lock.json
- CVE-2026-33750 in package-lock.json
- CVE-2026-14257 in package-lock.json
- CVE-2026-69152 in package-lock.json
How to fix:
Review the findings in the Security tab. Update the affected dependencies if a patched version is available.
debug info
CI timings
CI timings · View report · View job
Wall time 9m36s vs 9m31s (+0.9%). 26 job(s) slower, 14 faster, 4 unchanged.
- JS & TS checks / apps/desktop / check:test:ui:shard-2of3: +65.0s
- Python tests / Run tests slice 5/12: +59.0s
- Python tests / Run tests slice 3/12: +55.0s
- Python tests / Run tests slice 4/12: +48.0s
- JS & TS checks / apps/desktop / check:test:desktop:platforms: +46.0s
v5 publication checkpointPublished candidate-local work at head Commits
Verified locally
Retained limitations
This is a draft progress checkpoint, not a merge, release, security, production-readiness, or full-program-completion claim. Existing PRs #35 and #41 remain untouched. |
v5 hosted/publication reconciliationHead verified: This note corrects the earlier statement that hosted CI had not run. The PR remains a draft and is not merge-ready. Hosted state at readback
Evidence boundaryThe local test counts and focused Desktop witnesses in the PR description remain controller-run, source-level evidence. The fresh full Desktop E2E result remains 17 failures; ARES-FULL and ISO stress remain incomplete. P13/P14 native provider/tool integration, external-provider calls, activation, live repair, recurrence, historical-goal transitions, merge, and release claims remain out of scope and unproven. |
v5 security refreshHead: Change
Controller-run validation
BoundaryThis is not a universal security guarantee: the Ares Node audits remain non-clean, and the broader v5 program still retains P09/P11/P12/P13–P16 proof debt. No production-readiness, merge-readiness, activation, provider-call, live-repair, or completion claim is intended. |
v5 current-gate reconciliationHead: Current hosted/local state
BoundaryThese are controller-run local/source-level and hosted-check observations. They do not establish full Ares qualification, sustained-load success, security certification, production readiness, native provider/tool integration, activation, live repair, recurrence, merge readiness, or full-program completion. |
v5 Desktop test-harness correctionHead intended for publication: This commit changes only Controller-run validation
The fresh full Desktop E2E run remains failed with 17 current failures; this targeted correction does not override that result. BoundaryNo provider call, credential change, activation, merge, production-readiness, or full Desktop-E2E claim is intended. |
v5 Desktop test-harness correction — exact-head rerunThe exact committed head The fresh full Desktop E2E result remains failed with 17 current failures; this targeted witness does not override that gate. The PR remains a draft and this update does not claim production readiness, security certification, merge readiness, activation, provider execution, or full-program completion. |
v5 workflow-lint baseline correctionHead: This exact-scope follow-up changes seven existing workflow files. It quotes the merge-base expansion, removes a redundant Controller-reported validation
The prior exact-head hosted BoundaryA new hosted run is required before claiming the hosted lint gate or aggregate is passing. This PR remains a draft; the existing 17-failure full Desktop E2E result, neutral OSV result, and Review label gate remain visible. No production, security-certification, merge-readiness, activation, provider-execution, or full-program-completion claim is intended. |
v5 workflow-lint baseline correctionHead: This one-token follow-up replaces the unused polling-loop variable Controller-reported validation
Hosted boundaryThe preceding hosted run at No production, security-certification, merge-readiness, provider-execution, or full-program-completion claim is intended. |
v5 scoped dependency/security refreshPublished commit: This draft update refreshes selected dependency pins and lockfiles, and removes an invalid Liquid raw-block wrapper from the bundled arXiv skill documentation:
Exact-commit lockfile-only audits reported zero findings:
Additional recorded validation:
Known limitations remain explicit:
Receipts are preserved under |
v5 hosted result for
|
v5 Website typecheck/build follow-upPublished commit: This follow-up:
Exact-commit validation:
The full build still emits existing broken-link and broken-anchor warnings; those warnings remain open and are not being represented as a clean documentation gate. This update also does not establish universal security, production readiness, merge readiness, or completion of the broader stabilization handoff. The unrelated untracked P09 test remains excluded. Receipts:
|
v5 P09 ISO harness environment-boundary correctionPublished commit: This two-file correction updates Controller-run validation
Corrected evidence boundary
Receipts: |
Summary
This draft PR publishes the verified, candidate-local portions of the v5 architecture-stabilization work against the current Ares
mainbase. It is intentionally limited to CI aggregation, Desktop busy-composer semantics, Context Governor lineage/restart handling, a Markdown property-fuzz timeout correction, and the reviewedhttpx2lock upgrade.The historical Ares PRs #35 and #41 are not rewritten or closed by this branch.
Changes
if: falseand checksum-pinned actionlint validation.httpx2/httpcore2lock path from 2.7.0 to 2.12.0.h2,hpack, andtornadopins to4.4.1,4.2.0, and6.5.8respectively.Local validation
detect-secretsscans: passed with empty findings.Known limitations / retained proof debt
Review label gateandAll required checks passfailed. Workflow dispatch was not separately dispatched.HERMES_COMPUTE_HOST_CHILD=1, which made the scratch dashboard disabledashboard.turn_isolation. Commit5e5bdff6419404b038b5e28080d77170697e279cremoves that child-only marker from the top-level certification dashboard environment; the exact committed 600-second ISO-ON rerun passed with 17 heavy turns, zero serving stalls, REST p99 13.81 ms, and WebSocket p99 3.16 ms. This is local source- and environment-specific certification evidence, not a universal performance, production-readiness, security, or overall completion claim.Boundary
No provider call, credential change, live migration, activation, ruleset change, merge, or historical identity transition is part of this PR. This draft must not be interpreted as fully validated, secure, production-ready, or release-ready.