Skip to content

[pull] main from czlonkowski:main - #90

Merged
pull[bot] merged 9 commits into
5474312:mainfrom
czlonkowski:main
Jul 3, 2026
Merged

[pull] main from czlonkowski:main#90
pull[bot] merged 9 commits into
5474312:mainfrom
czlonkowski:main

Conversation

@pull

@pull pull Bot commented Jul 3, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

dependabot Bot and others added 9 commits July 3, 2026 15:44
Bumps [github/gh-aw-actions/setup](https://github.com/github/gh-aw-actions) from ba90f2186d7ad780ec640f364005fa24e797b360 to abea67e08ee83539ea33aaae67bf0cddaa0b03b5.
- [Release notes](https://github.com/github/gh-aw-actions/releases)
- [Changelog](https://github.com/github/gh-aw-actions/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw-actions@ba90f21...abea67e)

---
updated-dependencies:
- dependency-name: github/gh-aw-actions/setup
  dependency-version: abea67e08ee83539ea33aaae67bf0cddaa0b03b5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 5 to 7.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@v5...v7)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the development-dependencies group in /ui-apps with 1 update: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite).


Updates `vite` from 8.1.0 to 8.1.3
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.1.3/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.1.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
…directory with 9 updates

Bumps the development-dependencies group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [axios](https://github.com/axios/axios) | `1.16.1` | `1.18.1` |
| [@adobe/css-tools](https://github.com/adobe/css-tools) | `4.4.4` | `4.5.0` |
| [@inquirer/ansi](https://github.com/SBoudrias/Inquirer.js) | `2.0.5` | `2.0.7` |
| [@inquirer/confirm](https://github.com/SBoudrias/Inquirer.js) | `6.0.13` | `6.1.1` |
| [expect-type](https://github.com/mmkal/expect-type) | `1.3.0` | `1.4.0` |
| [rollup](https://github.com/rollup/rollup) | `4.60.3` | `4.62.2` |
| [set-cookie-parser](https://github.com/nfriedly/set-cookie-parser) | `3.1.0` | `3.1.1` |
| [tinyglobby](https://github.com/SuperchupuDev/tinyglobby) | `0.2.16` | `0.2.17` |
| [tldts](https://github.com/remusao/tldts) | `7.0.30` | `7.4.6` |



Updates `axios` from 1.16.1 to 1.18.1
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.16.1...v1.18.1)

Updates `@adobe/css-tools` from 4.4.4 to 4.5.0
- [Changelog](https://github.com/adobe/css-tools/blob/main/docs/CHANGELOG.md)
- [Commits](https://github.com/adobe/css-tools/commits)

Updates `@inquirer/ansi` from 2.0.5 to 2.0.7
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/ansi@2.0.5...@inquirer/ansi@2.0.7)

Updates `@inquirer/confirm` from 6.0.13 to 6.1.1
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/confirm@6.0.13...@inquirer/confirm@6.1.1)

Updates `expect-type` from 1.3.0 to 1.4.0
- [Release notes](https://github.com/mmkal/expect-type/releases)
- [Commits](mmkal/expect-type@v1.3.0...v1.4.0)

Updates `rollup` from 4.60.3 to 4.62.2
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.60.3...v4.62.2)

Updates `set-cookie-parser` from 3.1.0 to 3.1.1
- [Changelog](https://github.com/nfriedly/set-cookie-parser/blob/master/CHANGELOG.md)
- [Commits](nfriedly/set-cookie-parser@v3.1.0...v3.1.1)

Updates `tinyglobby` from 0.2.16 to 0.2.17
- [Release notes](https://github.com/SuperchupuDev/tinyglobby/releases)
- [Changelog](https://github.com/SuperchupuDev/tinyglobby/blob/main/CHANGELOG.md)
- [Commits](SuperchupuDev/tinyglobby@0.2.16...0.2.17)

Updates `tldts` from 7.0.30 to 7.4.6
- [Release notes](https://github.com/remusao/tldts/releases)
- [Changelog](https://github.com/remusao/tldts/blob/master/CHANGELOG.md)
- [Commits](remusao/tldts@v7.0.30...v7.4.6)

---
updated-dependencies:
- dependency-name: "@adobe/css-tools"
  dependency-version: 4.5.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: "@inquirer/ansi"
  dependency-version: 2.0.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: "@inquirer/confirm"
  dependency-version: 6.1.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: axios
  dependency-version: 1.18.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: expect-type
  dependency-version: 1.4.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: rollup
  dependency-version: 4.62.2
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: set-cookie-parser
  dependency-version: 3.1.1
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: tinyglobby
  dependency-version: 0.2.17
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: tldts
  dependency-version: 7.4.5
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
…ndabot

Both are pinned to exact versions on purpose: zod v4 breaks the MCP SDK and the
SDK/zod pair is enforced by the "Fresh Install Dependency Check" CI guard (issues
#440, #444, #446, #447, #450). Their versions are also mirrored in
package.runtime.json, which Dependabot cannot update. As a result every
production-dependencies group PR that bumps the SDK (e.g. #909, 1.28.0 -> 1.29.0)
fails CI and cannot merge. Excluding them from Dependabot keeps the weekly
production group PR mergeable; the SDK/zod are bumped manually with a
compatibility-tested change that also mirrors package.runtime.json.

Conceived by Romuald Członkowski - www.aiadvisors.pl/en
)

* ci: skip live n8n integration tests when no instance is configured

The `test` job's "Run integration tests" step talks to a live n8n instance via
the N8N_API_* secrets. Those secrets are unavailable on Dependabot and fork PRs,
where ~21 of 58 integration files fail outright and turn the required `test`
check permanently red — the dependency PRs we most want to auto-merge can never
go green.

Gate the step on `env.N8N_API_URL != ''` (surfaced at job level because the
`secrets` context is not usable in `if:`), so it is skipped cleanly when no
instance is configured. On in-repo PRs the secret is present, so the suite still
runs and remains a blocking gate — this keeps the safety net where it works
instead of removing it for every PR. Add `--retry=2` to absorb the occasional
live-API flake ("expected false to be true") seen even when the instance is up.

Unit tests, lint, and typecheck remain the always-on blocking gate.

Conceived by Romuald Członkowski - www.aiadvisors.pl/en

* ci: address Copilot review — split offline vs live integration, scope secret

- Don't broadcast the N8N_API_URL secret to every step: expose only a boolean
  HAS_N8N_INSTANCE flag at job level and keep N8N_API_* scoped to the live step.
- Split the integration run so the offline suites (database, security,
  mcp-protocol, workflow-diff, templates, docker, …) always run and stay a
  blocking gate on every PR — only the live n8n-api / ai-validation suites are
  gated on the flag and skipped when no instance is configured. This preserves
  offline-integration coverage on Dependabot/fork PRs instead of skipping it.
- Drop --retry: the base Vitest config sets retry: 0 on purpose (fix flaky tests,
  don't mask them). The two flaky live-API cases in update-partial-workflow.test.ts
  should be fixed with proper eventual-consistency waits — tracked as follow-up.

Conceived by Romuald Członkowski - www.aiadvisors.pl/en

* ci: address Copilot follow-up — gate live tests on both n8n secrets

- HAS_N8N_INSTANCE now requires both N8N_API_URL and N8N_API_KEY: the live suites
  call getN8nCredentials(), which throws if either is missing, so a partially
  configured instance (URL set, key absent) would run the step and fail. Both are
  absent on Dependabot/fork PRs.
- Reword the flag comment to state the real rationale (avoid exposing the secret
  values to every step; both empty on Dependabot/fork PRs) instead of a claim
  about `if:` mechanics.

Conceived by Romuald Członkowski - www.aiadvisors.pl/en
…ilies (v2.63.0) (#911)

* fix: eliminate verified validator false positives across all rule families (Concieved by Romuald Członkowski - www.aiadvisors.pl/en)

A systematic audit validated 1,116 recent published n8n.io templates under
all four profiles and inventoried all 439 validator rule emission points:
78% of published templates were declared invalid, with the dominant error
classes 90-100% false positives (each class adversarially verified with
live n8n reproductions before fixing).

Fixes in this release:
- applyNodeDefaults is visibility-aware (fixpoint), ending wrong-resource
  operation defaults that fabricated "Invalid value for operation" errors
- error-handling style checks are lint, not validity: responseNode error
  removed, onError/error-output checks node-type-aware via getMainOutputCount
- template-literal ${} in expressions is valid (real fix for #338); stale
  "common mistakes" warnings (optional chaining, bracket access) removed
- IF/Switch/Filter structure checks are typeVersion/shape-aware; operator
  singleValue and conditions.options metadata no longer demanded
- Merge input bounds, cycle detection, and bracket-balance checks respect
  n8n's lenient runtime behavior
- Code scanner: tokenizer handles template-literal interpolation; bare-object
  returns valid in runOnceForAllItems; regex/SQL checks use word and
  statement boundaries (dropdown/updated_at/regex.exec no longer flagged)
- AI validators check parameters the nodes actually have (sseEndpoint vs
  serverUrl, built-in tool descriptions, needsFallback dual models)
- reachability BFS follows ai_* connections in reverse: AI sub-nodes of a
  reachable agent are reachable
- nodes.db: extractFromFile restored; core-node completeness gate added to
  rebuild; optional-dep node modules no longer silently dropped; similarity
  suggester sentinel/category-match defects fixed
- profile gating repaired: advisories gate to ai-friendly/strict; security/
  deprecation warnings survive everywhere; severities recalibrated

Result on the template corpus: falsely-invalid workflows 77% -> 39%
(runtime), errors -39%, warnings -91%, and profiles differentiate again.
~150 new regression tests pin both directions (FP fixed, TP still fires).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: scan stripped view for input references in Code nodes — address Copilot review (Concieved by Romuald Członkowski - www.aiadvisors.pl/en)

The no-input advisory checked raw code, so an input pattern appearing only
inside a string literal or comment suppressed the warning. It now scans the
string/comment/regex-stripped view; template-literal interpolation code is
preserved, so real references like `${$json.name}` still count.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: seed Docker DB from bundled copy; exclude stopWorkflow from error handling — address Copilot review (Concieved by Romuald Członkowski - www.aiadvisors.pl/en)

Two fixes:

1. Docker DB initialization: the entrypoint ran rebuild.js inside the
   runtime container, which cannot succeed (no n8n packages in the slim
   image) — previously failing silently, exposed by this release's
   fail-loud rebuild. The image now ships a pristine seed at
   /app/.db-seed/nodes.db (volume mounts mask /app/data) and the
   entrypoint copies it to new DB paths; unwritable volumes warn and
   continue instead of killing the container (the historical contract).

2. Per-node error-handling advisory: onError: 'stopWorkflow' (n8n's
   fail-loud default) no longer counts as error handling, consistent
   with workflowHasErrorHandling. Guard tests both ways.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: scan stripped view in Code-node security checks — address Copilot review (Concieved by Romuald Członkowski - www.aiadvisors.pl/en)

The eval/Function/exec security heuristics ran against raw code, so a
string literal mentioning "eval(" (e.g. an LLM prompt) triggered
security warnings — which survive every profile by design. They now scan
the string/comment/regex-stripped view; template-literal interpolation
code is preserved, so real dynamic-eval sinks still warn. The require()
checks keep raw code on purpose: they need the module-name string
argument that the stripped view blanks.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…3.0 (Concieved by Romuald Członkowski - www.aiadvisors.pl/en) (#916)

Syncs data/skills from n8n-skills v1.22.0 (czlonkowski/n8n-skills#36):
validator guidance now describes 2.63.0 behavior (real profile gating,
fixed false-positive classes, precise template-literal/optional-chaining
guidance, bare-object return auto-wrap), plus all skills added to the
pack since the last sync (agents, error-handling, binary-and-data,
code-tool, subworkflows, multi-instance, self-hosting, router).

sync-skills.ts now skips skill-creator eval workspace directories
(skills/*-workspace/) so local eval debris never ships in artifacts.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@pull pull Bot locked and limited conversation to collaborators Jul 3, 2026
@pull pull Bot added the ⤵️ pull label Jul 3, 2026
@pull
pull Bot merged commit b604bea into 5474312:main Jul 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant