[pull] main from czlonkowski:main - #90
Merged
Merged
Conversation
Bumps [github/gh-aw-actions/setup](https://github.com/github/gh-aw-actions) from ba90f2186d7ad780ec640f364005fa24e797b360 to abea67e08ee83539ea33aaae67bf0cddaa0b03b5. - [Release notes](https://github.com/github/gh-aw-actions/releases) - [Changelog](https://github.com/github/gh-aw-actions/blob/main/CHANGELOG.md) - [Commits](github/gh-aw-actions@ba90f21...abea67e) --- updated-dependencies: - dependency-name: github/gh-aw-actions/setup dependency-version: abea67e08ee83539ea33aaae67bf0cddaa0b03b5 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 5 to 7. - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@v5...v7) --- updated-dependencies: - dependency-name: codecov/codecov-action dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3. - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@v2...v3) --- updated-dependencies: - dependency-name: softprops/action-gh-release dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the development-dependencies group in /ui-apps with 1 update: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Updates `vite` from 8.1.0 to 8.1.3 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.1.3/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.1.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
…directory with 9 updates Bumps the development-dependencies group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [axios](https://github.com/axios/axios) | `1.16.1` | `1.18.1` | | [@adobe/css-tools](https://github.com/adobe/css-tools) | `4.4.4` | `4.5.0` | | [@inquirer/ansi](https://github.com/SBoudrias/Inquirer.js) | `2.0.5` | `2.0.7` | | [@inquirer/confirm](https://github.com/SBoudrias/Inquirer.js) | `6.0.13` | `6.1.1` | | [expect-type](https://github.com/mmkal/expect-type) | `1.3.0` | `1.4.0` | | [rollup](https://github.com/rollup/rollup) | `4.60.3` | `4.62.2` | | [set-cookie-parser](https://github.com/nfriedly/set-cookie-parser) | `3.1.0` | `3.1.1` | | [tinyglobby](https://github.com/SuperchupuDev/tinyglobby) | `0.2.16` | `0.2.17` | | [tldts](https://github.com/remusao/tldts) | `7.0.30` | `7.4.6` | Updates `axios` from 1.16.1 to 1.18.1 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.16.1...v1.18.1) Updates `@adobe/css-tools` from 4.4.4 to 4.5.0 - [Changelog](https://github.com/adobe/css-tools/blob/main/docs/CHANGELOG.md) - [Commits](https://github.com/adobe/css-tools/commits) Updates `@inquirer/ansi` from 2.0.5 to 2.0.7 - [Release notes](https://github.com/SBoudrias/Inquirer.js/releases) - [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/ansi@2.0.5...@inquirer/ansi@2.0.7) Updates `@inquirer/confirm` from 6.0.13 to 6.1.1 - [Release notes](https://github.com/SBoudrias/Inquirer.js/releases) - [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/confirm@6.0.13...@inquirer/confirm@6.1.1) Updates `expect-type` from 1.3.0 to 1.4.0 - [Release notes](https://github.com/mmkal/expect-type/releases) - [Commits](mmkal/expect-type@v1.3.0...v1.4.0) Updates `rollup` from 4.60.3 to 4.62.2 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md) - [Commits](rollup/rollup@v4.60.3...v4.62.2) Updates `set-cookie-parser` from 3.1.0 to 3.1.1 - [Changelog](https://github.com/nfriedly/set-cookie-parser/blob/master/CHANGELOG.md) - [Commits](nfriedly/set-cookie-parser@v3.1.0...v3.1.1) Updates `tinyglobby` from 0.2.16 to 0.2.17 - [Release notes](https://github.com/SuperchupuDev/tinyglobby/releases) - [Changelog](https://github.com/SuperchupuDev/tinyglobby/blob/main/CHANGELOG.md) - [Commits](SuperchupuDev/tinyglobby@0.2.16...0.2.17) Updates `tldts` from 7.0.30 to 7.4.6 - [Release notes](https://github.com/remusao/tldts/releases) - [Changelog](https://github.com/remusao/tldts/blob/master/CHANGELOG.md) - [Commits](remusao/tldts@v7.0.30...v7.4.6) --- updated-dependencies: - dependency-name: "@adobe/css-tools" dependency-version: 4.5.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: "@inquirer/ansi" dependency-version: 2.0.7 dependency-type: indirect update-type: version-update:semver-patch dependency-group: development-dependencies - dependency-name: "@inquirer/confirm" dependency-version: 6.1.1 dependency-type: indirect update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: axios dependency-version: 1.18.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: expect-type dependency-version: 1.4.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: rollup dependency-version: 4.62.2 dependency-type: indirect update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: set-cookie-parser dependency-version: 3.1.1 dependency-type: indirect update-type: version-update:semver-patch dependency-group: development-dependencies - dependency-name: tinyglobby dependency-version: 0.2.17 dependency-type: indirect update-type: version-update:semver-patch dependency-group: development-dependencies - dependency-name: tldts dependency-version: 7.4.5 dependency-type: indirect update-type: version-update:semver-minor dependency-group: development-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
…ndabot Both are pinned to exact versions on purpose: zod v4 breaks the MCP SDK and the SDK/zod pair is enforced by the "Fresh Install Dependency Check" CI guard (issues #440, #444, #446, #447, #450). Their versions are also mirrored in package.runtime.json, which Dependabot cannot update. As a result every production-dependencies group PR that bumps the SDK (e.g. #909, 1.28.0 -> 1.29.0) fails CI and cannot merge. Excluding them from Dependabot keeps the weekly production group PR mergeable; the SDK/zod are bumped manually with a compatibility-tested change that also mirrors package.runtime.json. Conceived by Romuald Członkowski - www.aiadvisors.pl/en
) * ci: skip live n8n integration tests when no instance is configured The `test` job's "Run integration tests" step talks to a live n8n instance via the N8N_API_* secrets. Those secrets are unavailable on Dependabot and fork PRs, where ~21 of 58 integration files fail outright and turn the required `test` check permanently red — the dependency PRs we most want to auto-merge can never go green. Gate the step on `env.N8N_API_URL != ''` (surfaced at job level because the `secrets` context is not usable in `if:`), so it is skipped cleanly when no instance is configured. On in-repo PRs the secret is present, so the suite still runs and remains a blocking gate — this keeps the safety net where it works instead of removing it for every PR. Add `--retry=2` to absorb the occasional live-API flake ("expected false to be true") seen even when the instance is up. Unit tests, lint, and typecheck remain the always-on blocking gate. Conceived by Romuald Członkowski - www.aiadvisors.pl/en * ci: address Copilot review — split offline vs live integration, scope secret - Don't broadcast the N8N_API_URL secret to every step: expose only a boolean HAS_N8N_INSTANCE flag at job level and keep N8N_API_* scoped to the live step. - Split the integration run so the offline suites (database, security, mcp-protocol, workflow-diff, templates, docker, …) always run and stay a blocking gate on every PR — only the live n8n-api / ai-validation suites are gated on the flag and skipped when no instance is configured. This preserves offline-integration coverage on Dependabot/fork PRs instead of skipping it. - Drop --retry: the base Vitest config sets retry: 0 on purpose (fix flaky tests, don't mask them). The two flaky live-API cases in update-partial-workflow.test.ts should be fixed with proper eventual-consistency waits — tracked as follow-up. Conceived by Romuald Członkowski - www.aiadvisors.pl/en * ci: address Copilot follow-up — gate live tests on both n8n secrets - HAS_N8N_INSTANCE now requires both N8N_API_URL and N8N_API_KEY: the live suites call getN8nCredentials(), which throws if either is missing, so a partially configured instance (URL set, key absent) would run the step and fail. Both are absent on Dependabot/fork PRs. - Reword the flag comment to state the real rationale (avoid exposing the secret values to every step; both empty on Dependabot/fork PRs) instead of a claim about `if:` mechanics. Conceived by Romuald Członkowski - www.aiadvisors.pl/en
…ilies (v2.63.0) (#911) * fix: eliminate verified validator false positives across all rule families (Concieved by Romuald Członkowski - www.aiadvisors.pl/en) A systematic audit validated 1,116 recent published n8n.io templates under all four profiles and inventoried all 439 validator rule emission points: 78% of published templates were declared invalid, with the dominant error classes 90-100% false positives (each class adversarially verified with live n8n reproductions before fixing). Fixes in this release: - applyNodeDefaults is visibility-aware (fixpoint), ending wrong-resource operation defaults that fabricated "Invalid value for operation" errors - error-handling style checks are lint, not validity: responseNode error removed, onError/error-output checks node-type-aware via getMainOutputCount - template-literal ${} in expressions is valid (real fix for #338); stale "common mistakes" warnings (optional chaining, bracket access) removed - IF/Switch/Filter structure checks are typeVersion/shape-aware; operator singleValue and conditions.options metadata no longer demanded - Merge input bounds, cycle detection, and bracket-balance checks respect n8n's lenient runtime behavior - Code scanner: tokenizer handles template-literal interpolation; bare-object returns valid in runOnceForAllItems; regex/SQL checks use word and statement boundaries (dropdown/updated_at/regex.exec no longer flagged) - AI validators check parameters the nodes actually have (sseEndpoint vs serverUrl, built-in tool descriptions, needsFallback dual models) - reachability BFS follows ai_* connections in reverse: AI sub-nodes of a reachable agent are reachable - nodes.db: extractFromFile restored; core-node completeness gate added to rebuild; optional-dep node modules no longer silently dropped; similarity suggester sentinel/category-match defects fixed - profile gating repaired: advisories gate to ai-friendly/strict; security/ deprecation warnings survive everywhere; severities recalibrated Result on the template corpus: falsely-invalid workflows 77% -> 39% (runtime), errors -39%, warnings -91%, and profiles differentiate again. ~150 new regression tests pin both directions (FP fixed, TP still fires). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: scan stripped view for input references in Code nodes — address Copilot review (Concieved by Romuald Członkowski - www.aiadvisors.pl/en) The no-input advisory checked raw code, so an input pattern appearing only inside a string literal or comment suppressed the warning. It now scans the string/comment/regex-stripped view; template-literal interpolation code is preserved, so real references like `${$json.name}` still count. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: seed Docker DB from bundled copy; exclude stopWorkflow from error handling — address Copilot review (Concieved by Romuald Członkowski - www.aiadvisors.pl/en) Two fixes: 1. Docker DB initialization: the entrypoint ran rebuild.js inside the runtime container, which cannot succeed (no n8n packages in the slim image) — previously failing silently, exposed by this release's fail-loud rebuild. The image now ships a pristine seed at /app/.db-seed/nodes.db (volume mounts mask /app/data) and the entrypoint copies it to new DB paths; unwritable volumes warn and continue instead of killing the container (the historical contract). 2. Per-node error-handling advisory: onError: 'stopWorkflow' (n8n's fail-loud default) no longer counts as error handling, consistent with workflowHasErrorHandling. Guard tests both ways. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: scan stripped view in Code-node security checks — address Copilot review (Concieved by Romuald Członkowski - www.aiadvisors.pl/en) The eval/Function/exec security heuristics ran against raw code, so a string literal mentioning "eval(" (e.g. an LLM prompt) triggered security warnings — which survive every profile by design. They now scan the string/comment/regex-stripped view; template-literal interpolation code is preserved, so real dynamic-eval sinks still warn. The require() checks keep raw code on purpose: they need the module-name string argument that the stripped view blanks. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…3.0 (Concieved by Romuald Członkowski - www.aiadvisors.pl/en) (#916) Syncs data/skills from n8n-skills v1.22.0 (czlonkowski/n8n-skills#36): validator guidance now describes 2.63.0 behavior (real profile gating, fixed false-positive classes, precise template-literal/optional-chaining guidance, bare-object return auto-wrap), plus all skills added to the pack since the last sync (agents, error-handling, binary-and-data, code-tool, subworkflows, multi-instance, self-hosting, router). sync-skills.ts now skips skill-creator eval workspace directories (skills/*-workspace/) so local eval debris never ships in artifacts. Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )