Skip to content

Add experimental reused Vercel sandboxes - #3572

Draft
ctgowrie wants to merge 11 commits into
spike/vercel-image-sandboxfrom
spike/vercel-reused-sandbox
Draft

ctgowrie wants to merge 11 commits into
spike/vercel-image-sandboxfrom
spike/vercel-reused-sandbox

Conversation

@ctgowrie

@ctgowrie ctgowrie commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #3477. Adds an experimental Vercel provider that deliberately excludes the eve session ID from native image-sandbox identity, so mutually trusted eve sessions using the same prepared image, Drive resources, and immutable environment options converge on one persistent native sandbox.

Each eve session still receives its own logical handle and immutable provider state. stop(), runtime shutdown, and delete() detach that logical view without stopping or deleting shared native compute, and mutable setNetworkPolicy() is omitted because every attached session shares one network boundary. This is intentionally not an isolation primitive: attached sessions share processes, files, ports, credentials, and network policy.

Review should focus on shared identity derivation, omission of session-specific tags and mutable networking, and non-destructive lifecycle mapping. The implementation uses only public Vercel Sandbox/Image/Drive/OIDC surfaces and contains no private endpoints, feature flags, infrastructure names, or real identifiers.

Validation

Direct TypeScript compilation passes. Focused reused-provider and public API tests pass, including convergence across distinct eve session IDs, direct resume from shared state, and logical lifecycle operations that do not delete native compute. A deterministic Vercel-world fixture writes from one eve session and reads from a second, explicitly distinct eve session, proving cross-session native filesystem reuse; local model runs skip that provider-specific assertion. Logical stop/delete behavior remains covered by deterministic provider unit tests.

Checklist

  • This change was requested or approved by a maintainer
  • I ran the relevant checks from CONTRIBUTING.md
  • I added tests and documentation where relevant
  • I added a changeset if this touches the published eve package
  • DCO sign-off passes for every commit (git commit --signoff)

Diff size

Docs — 3 files · +51 / -0

Documents the experimental provider, its trusted-session boundary, and its release-note impact.

Implementation — 6 files · +132 / -3

Adds the distinct reused provider, public environment/export surface, shared identity configuration, fixed network policy, and runtime pruning support.

Tests — 15 files · +271 / -6

Covers shared identity and lifecycle semantics, public portability, hosted pruning, and a Vercel-world fixture proving cross-session filesystem reuse across distinct eve sessions. Non-destructive logical stop/delete remains covered by unit tests.

@vercel

vercel Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
colton-eve-dynamic-schedules Error Error v0 Sep 22, 2026 5:06pm UTC
eve-docs Ready Ready Preview, v0 Sep 22, 2026 5:06pm UTC
eve-pkg Ready Ready Preview, v0 Sep 22, 2026 5:06pm UTC

@vercel-security-reviewer

Copy link
Copy Markdown

Security review details

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bundle + Package Summary: apps/fixtures/weather-agent

Key takeaways

  • No notable deltas vs spike/vercel-image-sandbox (a5e4b5e).

Delta vs spike/vercel-image-sandbox (a5e4b5e)

Area Metric Baseline Current Delta
Package Packed tarball 8.60 MB 8.60 MB +1.5 kB ⚠️
Package Unpacked publish size 32.02 MB 32.03 MB +4.6 kB ⚠️
Package Installed footprint 78.20 MB 78.20 MB +4.6 kB ⚠️
Package Published files 3781 3787 +6
Package Installed files 7741 7747 +6
Package Installed package instances 33 33 0
Package Distinct installed package names 32 32 0
Package Installed dependency edges 51 51 0
Package Installed optional peer edges 9 9 0
Runtime Unique function payloads 2 2 0
Runtime Total function bytes 21.97 MB 21.97 MB -80 B ✅
Runtime Public routes 18 18 0
Changed function payloads vs spike/vercel-image-sandbox (a5e4b5e) (2)
Function Status Baseline Current Delta Route changes
functions/__server.func changed 10.98 MB 10.98 MB -40 B ✅ none
functions/.well-known/workflow/v1/flow.func changed 10.98 MB 10.98 MB -40 B ✅ none

eve init install

Metric Baseline Current Delta
Installed footprint 116.42 MB 116.42 MB +4.6 kB ⚠️
Installed packages 98 98 0
dependencies 4 4 0
devDependencies 2 2 0
Dependency package bytes 49.51 MB 49.52 MB +4.6 kB ⚠️
devDependency package bytes 5.04 MB 5.04 MB 0 B ➖
Build Metadata
  • Preset: vercel
  • Nitro: nitro@3.0.260903-beta
  • Output directory: apps/fixtures/weather-agent/.vercel/output
  • Build metadata timestamp: 2026-09-22T17:07:18.469Z
  • Route aliases: 18 public, 1 internal (19 total aliases)
  • Vercel routes in config: 21
  • Severity legend: 🔴 dominant/large, 🟠 notable, 🟡 watch, ⚪ small
Package Drill-Down

Package Details

  • Package: eve@0.63.1
  • Package directory: packages/eve
  • Tarball: 8.60 MB (eve-0.63.1.tgz)
  • Unpacked payload: 32.03 MB across 3787 published files
  • Installed footprint: 78.20 MB across 7747 installed files
  • Installed root package: 31.38 MB
  • Installed dependencies: 46.83 MB
  • Installed package instances: 33
  • Distinct installed package names: 32
  • Installed dependency edges: 51
  • Installed optional peer edges: 9
  • Runtime dependencies: 2
  • Peer dependencies: 7 (6 optional)

Installed footprint is measured from an isolated temporary npm install of the packed tarball.
Graph metrics read only package.json files in package directories directly beneath a node_modules boundary, including nested boundaries. Each directory is one package instance; distinct names come from those manifests. Dependency edges count each unique name in dependencies or optionalDependencies per instance; optional peer edges count peerDependencies marked optional.

Heavy installed dependencies

  • eve: 31.38 MB (40.1%)
  • @rolldown/binding-linux-x64-gnu: 19.10 MB (24.4%)
  • ai: 7.66 MB (9.8%)
  • zod: 6.67 MB (8.5%)
  • undici: 3.51 MB (4.5%)
Publish payload breakdown
Published file size
🔴 dist/src/compiled/shadcn-registry/index.js       [#############...........] 9.70 MB 30.3%
🟠 dist/src/compiled/@photon-ai/chat-adapter-ime... [###.....................] 2.29 MB 7.2%
🟠 dist/src/compiled/@ai-sdk/code-mode/index.js     [#.......................] 1.03 MB 3.2%
🟡 dist/src/compiled/@vercel/blob/index.js          [#.......................] 902.9 kB 2.8%
🟡 dist/src/compiled/_chunks/workflow/signal-exi... [#.......................] 514.5 kB 1.6%
🔴 Other published files                            [########################] 17.59 MB 54.9%
Installed footprint breakdown
Installed package size
🔴 eve                             [########################] 31.38 MB 40.1%
🔴 @rolldown/binding-linux-x64-gnu [###############.........] 19.10 MB 24.4%
🔴 ai                              [######..................] 7.66 MB 9.8%
🔴 zod                             [#####...................] 6.67 MB 8.5%
🟠 undici                          [###.....................] 3.51 MB 4.5%
🟠 nitro                           [#.......................] 1.89 MB 2.4%
🔴 Other installed packages        [######..................] 7.98 MB 10.2%
Runtime dependencies (2)
Package Range Notes
nitro 3.0.260903-beta
undici 8.9.0
Peer dependencies (7)
Package Range Notes
@opentelemetry/api ^1.0.0 optional peer
ai catalog:
braintrust ^3.0.0 optional peer
chat ^4.41.0 optional peer
dd-trace ^6.13.0 optional peer
just-bash ^3.1.0 optional peer
microsandbox ^0.5.0 optional peer
eve init install drill-down

eve init install details

  • Command: eve init my-agent
  • Package manager: npm
  • Installed footprint: 116.42 MB across 9641 installed files
  • Installed packages: 98 total (92 transitive-only)
  • dependencies: 4 direct packages totaling 49.52 MB
  • devDependencies: 2 direct packages totaling 5.04 MB
  • Other transitive package files: 61.87 MB

Installed footprint is measured from an isolated temporary eve init my-agent using the current packed eve tarball.

Heavy installed dependencies

  • eve: 31.38 MB (27.0%)
  • @typescript/typescript-linux-x64: 27.95 MB (24.0%)
  • @rolldown/binding-linux-x64-gnu: 19.10 MB (16.4%)
  • zod: 10.29 MB (8.8%)
  • ai: 7.66 MB (6.6%)
Installed footprint breakdown
Installed package size
🔴 eve                              [########################] 31.38 MB 27.0%
🔴 @typescript/typescript-linux-x64 [#####################...] 27.95 MB 24.0%
🔴 @rolldown/binding-linux-x64-gnu  [###############.........] 19.10 MB 16.4%
🔴 zod                              [########................] 10.29 MB 8.8%
🔴 ai                               [######..................] 7.66 MB 6.6%
🟠 undici                           [###.....................] 3.51 MB 3.0%
🔴 Other installed packages         [#############...........] 16.54 MB 14.2%
dependencies (4)
Package Range Installed size Share
@vercel/connect 2.2.0 188.7 kB 0.2%
ai ^7.0.105 7.66 MB 6.6%
eve file:eve-0.63.1.tgz 31.38 MB 27.0%
zod 4.5.4 10.29 MB 8.8%
devDependencies (2)
Package Range Installed size Share
@types/node 24.x 2.54 MB 2.2%
typescript 7.0.2 2.50 MB 2.1%
Function Drill-Down

Payload Size Graph

Unique function payload size and share of total
🔴 functions/.well-known/workflow/v1/flow.func     [########################] 10.98 MB 50.0%
🔴 functions/__server.func                         [########################] 10.98 MB 50.0%

Top Function Payloads

🟠 functions/.well-known/workflow/v1/flow.func • 1 public route • 10.98 MB
Metric Value
Public routes /.well-known/workflow/v1/flow
Runtime nodejs24.x
Handler index.mjs
Payload 10.98 MB
Function files 10.98 MB across 120 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.88 MB (26.2%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                        [##############..........] 2.88 MB 26.2%
🟡 _libs/undici.mjs                 [#####...................] 980.8 kB 8.9%
🟡 _chunks/sandbox.mjs              [####....................] 809.9 kB 7.4%
🟡 _chunks/signal-exit-B9U6kH7R.mjs [###.....................] 616.2 kB 5.6%
🟡 _chunks/oidc.mjs                 [###.....................] 570.8 kB 5.2%
🔴 Other bundled files              [########################] 5.12 MB 46.6%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x",
  "maxDuration": "max",
  "experimentalTriggers": [
    {
      "type": "queue/v2beta",
      "topic": "__eve776561746865722d6167656e74_wkf_workflow_*",
      "consumer": "default",
      "retryAfterSeconds": 5,
      "initialDelaySeconds": 0
    }
  ],
  "environment": {
    "WORKFLOW_PRECONDITION_GUARD": "1"
  }
}

🟠 functions/__server.func • 17 public routes, 1 internal alias • 10.98 MB
Metric Value
Public routes /
/.well-known/workflow/v1/webhook/[token]
/eve/v1/activity/[token]
/eve/v1/callback/[token]
/eve/v1/connections/[name]/callback/[attemptId]/[token]
/eve/v1/connections/[name]/callback/[token]
/eve/v1/health
/eve/v1/info
/eve/v1/session
/eve/v1/session/[parentSessionId]/subagents/[callId]/[childSessionId]/stream
/eve/v1/session/[sessionId]
/eve/v1/session/[sessionId]/cancel
/eve/v1/session/[sessionId]/clear
/eve/v1/session/[sessionId]/compact
/eve/v1/session/[sessionId]/reset
/eve/v1/session/[sessionId]/stream
/eve/v1/task-input/[token]
Internal aliases /__server
Runtime nodejs24.x
Handler index.mjs
Payload 10.98 MB
Function files 10.98 MB across 120 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.88 MB (26.2%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                        [##############..........] 2.88 MB 26.2%
🟡 _libs/undici.mjs                 [#####...................] 980.8 kB 8.9%
🟡 _chunks/sandbox.mjs              [####....................] 809.9 kB 7.4%
🟡 _chunks/signal-exit-B9U6kH7R.mjs [###.....................] 616.2 kB 5.6%
🟡 _chunks/oidc.mjs                 [###.....................] 570.8 kB 5.2%
🔴 Other bundled files              [########################] 5.12 MB 46.6%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x"
}

Build Timing: e2e/fixtures/agent-tools-sandbox

This is an informational timing measurement inside eve build, from preflight through publication. Output-size measurement and profile writing are excluded.

Build mode: deployable Vercel build with sandbox template prewarm included.

  • Build pipeline: 4.39 s -> 4.35 s (-42.6 ms) vs spike/vercel-image-sandbox (a5e4b5e).
  • Timing is informational: shared GitHub runners are too variable for a hard timing budget.
Detailed phase timings vs `spike/vercel-image-sandbox (a5e4b5e)`
Phase Baseline Current Delta
extension.check 0.4 ms 0.5 ms +0.1 ms
project.resolve 0.3 ms 0.4 ms +0.1 ms
workspace.create 0.5 ms 0.6 ms +0.1 ms
host.prepare 799.8 ms 741.4 ms -58.4 ms
vercel.service-prefix.resolve 2.0 ms 2.1 ms +0.1 ms
nitro.create 303.4 ms 355.3 ms +51.9 ms
sandbox.prewarm 328.2 ms 304.7 ms -23.5 ms
nitro.cache.prepare 0.3 ms 0.3 ms 0.0 ms
nitro.prepare 0.7 ms 0.8 ms +0.1 ms
nitro.public-assets 0.8 ms 0.8 ms 0.0 ms
nitro.prerender 0.6 ms 0.5 ms -0.1 ms
nitro.bundle 2.78 s 2.77 s -16.1 ms
nitro.cache.write 0.4 ms 0.3 ms -0.1 ms
vercel.workflow-function.materialize 63.4 ms 76.8 ms +13.4 ms
agent-summary.emit 0.7 ms 0.7 ms 0.0 ms
nitro.close 0.2 ms 0.1 ms -0.1 ms
output.publish 3.7 ms 3.6 ms -0.1 ms
workspace.remove 2.7 ms 2.7 ms 0.0 ms

{ region: environmentOptions?.region },
{
...input,
identityPrefix: VERCEL_REUSED_IMAGE_PROVIDER_NAME,

@vercel vercel Bot Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The reused Vercel image provider silently drops all environment runtime options except networkPolicy, resources, and timeout, so options like ports type-check but never reach Sandbox.create.

Fix on Vercel

FixedNetworkSandboxSession
> {
const underlying = createVercelImageSandboxProvider(
{ region: environmentOptions?.region },

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Keep the fixed configuration in one generation identity

This split gives the underlying provider two incompatible identities. Persisted generation hashes the artifact plus its createOptions, which here contain the region and default timeout but not the authored policy, resources, or timeout. The native name hashes the artifact, policy, and resources, but omits region and timeout. resume() then passes none of the fixed runtime options again. A durable session created under allow-all therefore still validates and reconnects after a redeploy changes this environment to deny-all, retaining the permissive policy while this provider removes the setter that could correct it. Timeout changes also reuse the old native sandbox, and a region-only change can attach to the old region when the artifact has no region-specific mounts. Derive one normalized, versioned reused-generation value from the artifact, region, policy, resources, and timeout, then use it for both native naming and persisted-state validation. Please cover policy-tightening resume plus region and timeout rotation in tests.

{
...input,
identityPrefix: VERCEL_REUSED_IMAGE_PROVIDER_NAME,
resolveNativeSession: () => ({ identity: {}, tags: {} }),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Scope reuse to an explicit trust boundary

An empty native identity makes reuse project-wide whenever the artifact and selected options match. In the supported no-Dockerfile/no-managed-resource case, preparation produces the common eve base image with mounts: [], so two independent agents or deployments in one Vercel project resolve the same native name even if they are separate security domains. The docs require mutually trusted sessions, but callers have no value with which to establish that boundary. Add a required non-empty reuse namespace, or inject a stable per-application/per-sandbox-definition namespace, and hash it into the native identity. Add a test proving otherwise identical environments with different namespaces cannot attach to each other.

return reusedHandle(await underlying.resume(context, artifact, state));
},
async start(context, _options, artifact) {
const result = await underlying.start(context, runtimeOptions, artifact);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Coordinate creation and readiness across shared openers

The delegated image provider does a non-atomic get(name) followed by create(name). Two concurrent first opens can both observe no sandbox; a duplicate-name 409 is then treated as image-pending and retries the same create up to 45 times without re-reading the name. There is also a readiness window after creation: only the creator hydrates immutable workspace and skill resources, while another opener that finds the sandbox takes the existing path and can run its selector before hydration finishes. A creator setup failure can then delete the sandbox that opener attached to. Use provider-backed ownership/readiness keyed by the shared generation, re-fetch and attach after an already-exists conflict, and publish readiness only after base setup and hydration complete. The current unit and e2e cases are sequential, so please add deterministic concurrent-start, conflict-then-attach, and failed-creator tests.

const { setNetworkPolicy: _setNetworkPolicy, ...sandbox } = handle.sandbox;
return {
sandbox,
onRuntimeShutdown: preserveReusedCompute,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Do not reuse an uncommitted failed initialization

When a sandbox selector throws after open(), ensure.ts calls onSessionDelete() and clears the logical state. Replacing that hook with a no-op leaves any partial files, credentials, and processes from the failed selector in the shared native sandbox. The next session finds that sandbox through the existing path, which does not restore a clean workspace, so retries become nondeterministic and can expose the failed session's partial state. This also makes the page's existing promise that failed initialization deletes a newly started sandbox false for this provider. Distinguish framework cleanup of an uncommitted first initialization from user-requested logical deletion, then delete or quarantine that attempt before allowing attachment. Please add a selector-failure-then-retry test.

Comment thread docs/sandbox/vercel.mdx

## Experimental reused Dockerfile environment

`ExperimentalVercelReusedDockerfile` reuses one persistent native Vercel Sandbox across eve sessions. Use it only when every attached session belongs to the same trust boundary and concurrent access to one filesystem and network policy is safe.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] State the full shared security boundary

The warning mentions only the filesystem and network policy, but attached sessions also share processes, ports, and every credential available inside the sandbox. That omission can lead readers to combine sessions that should remain isolated. Please say this directly, for example: "Use it only for mutually trusted sessions. Sessions share processes, files, ports, any credentials available in the sandbox, and one fixed network policy; ensure concurrent access to those resources is safe."

Comment thread docs/sandbox/vercel.mdx

The provider derives reuse identity from the prepared image, managed resources, immutable environment options, and its contract version. Sessions using the same environment generation converge on the same native compute; changing those inputs rotates it. `open()` accepts no options.

Each eve session receives its own logical view, but commands and files operate on the reused native Sandbox. Session `stop()` and `delete()` calls detach logically and do not stop or delete native compute. The session omits `setNetworkPolicy()` because policy is shared and fixed in environment configuration.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Keep the following network instructions from contradicting this API

This correctly says the reused policy is fixed in environment(), but the immediately following Network policy section says to pass the policy to open() and explicitly says it does not belong in the environment definition. open() for this provider accepts no arguments. Please scope the following network and live-option sections to VercelSandbox, or move this reused-provider section after them, so readers do not apply those instructions to this environment.

@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from 749302a to 5675d5e Compare September 21, 2026 14:53
@vercel
vercel Bot temporarily deployed to Preview – eve-pkg September 21, 2026 14:54 Inactive
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from 5675d5e to 7ce2a63 Compare September 21, 2026 15:19
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from a912585 to d752e04 Compare September 21, 2026 15:27
@vercel
vercel Bot temporarily deployed to Preview – eve-pkg September 21, 2026 15:27 Inactive
@vercel
vercel Bot temporarily deployed to Preview – eve-pkg September 21, 2026 15:35 Inactive
@ctgowrie
ctgowrie force-pushed the spike/vercel-image-sandbox branch from 3e2970a to 4fab28a Compare September 21, 2026 15:37
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from 35b71c4 to ad9da8a Compare September 21, 2026 15:37
@vercel
vercel Bot temporarily deployed to Preview – eve-pkg September 21, 2026 15:46 Inactive
@ctgowrie
ctgowrie force-pushed the spike/vercel-image-sandbox branch from 4fab28a to c0b970a Compare September 21, 2026 15:54
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from 9bd5b48 to 8f3c735 Compare September 21, 2026 15:54
@ctgowrie
ctgowrie force-pushed the spike/vercel-image-sandbox branch from c0b970a to fbd2995 Compare September 21, 2026 16:08
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from 8f3c735 to 01567f2 Compare September 21, 2026 16:08
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from f60f58a to 1549ef7 Compare September 21, 2026 18:17
@ctgowrie
ctgowrie force-pushed the spike/vercel-image-sandbox branch from c2c1d9b to 31aa272 Compare September 21, 2026 18:18
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from 1549ef7 to dedf0d4 Compare September 21, 2026 18:18
@ctgowrie
ctgowrie force-pushed the spike/vercel-image-sandbox branch from 31aa272 to 5db3bba Compare September 21, 2026 18:26
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from dedf0d4 to f26a9b4 Compare September 21, 2026 18:26
@ctgowrie
ctgowrie force-pushed the spike/vercel-image-sandbox branch from 5db3bba to 0d11f2c Compare September 21, 2026 18:28
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from f26a9b4 to cda6795 Compare September 21, 2026 18:28
@ctgowrie
ctgowrie force-pushed the spike/vercel-image-sandbox branch from 0d11f2c to 78f823c Compare September 21, 2026 18:41
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from cda6795 to fa26735 Compare September 21, 2026 18:41
@ctgowrie
ctgowrie force-pushed the spike/vercel-image-sandbox branch from 78f823c to d07886a Compare September 21, 2026 19:03
@ctgowrie
ctgowrie force-pushed the spike/vercel-reused-sandbox branch from fa26735 to 56b1b2c Compare September 21, 2026 19:03
@socket-security

socket-security Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​workflow/​world-postgres@​5.0.0-beta.42 ⏵ 5.0.0-beta.4498 +1100100 +197 +1100

View full report

Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>
Signed-off-by: Casey Gowrie <ctgowrie@gmail.com>

This branch had an error being deployed

1 failed (outdated) and 2 active deployments
Preview – eve-docs — 610ce042 Deployed Sep 22, 2026 by vercel[bot]
Preview – eve-pkg — 610ce042 Deployed Sep 22, 2026 by vercel[bot]
Preview – colton-eve-dynamic-schedules — 1ddb211f Deployed Sep 21, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant