Repository navigation
fix(deps): update dependency @paperclipai/plugin-sdk to ^2026.916.0 - autoclosed - #213
Closed
renovate[bot] wants to merge 1 commit into
Closed
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2026.831.1→^2026.916.0bump,lockfileUpdate, orrollbackupdates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).Release Notes
paperclipai/paperclip (@paperclipai/plugin-sdk)
v2026.916.0Compare Source
Paperclip v2026.916.0
Paperclip v2026.916.0 carries 503 commits, promoted from
2026.916.0-beta.0published the same day. The headline is the Connections train: AI runtime credentials — Claude and Codex subscriptions, API keys, shared accounts — now live in Connections under the same grants and permission boundaries as every other account, follow the responsible person through hiring and task execution, and can be connected or repaired inline from the task that needs them. Around it: agents get their own email addresses through AgentMail, experimental chat connectors bring Slack, Discord, Telegram, Microsoft Teams, and (via Photon) iMessage conversations into tasks, GitHub access becomes durable per-person identities instead of one shared token, announcements arrive as native in-app cards, and the experimental Paperclip Runner grew from last release's groundwork into a complete execution engine — with the gate now open by default on self-hosted installs for explicitly configured agents.Breaking Changes
0236strips storedmodelProfilesblocks from agent configurations. There is now one model-selection path for normal work and recovery work. (#12683)adapterConfig.envas stored, soplainbindings (API keys, tokens) came back verbatim to any caller able to read the agent, including the agent itself viaGET /api/agents/me. All three response families now route through one redacting presenter. Integrations that scraped live credentials out of those responses will stop working — that was the leak. (#9860, @glovario)X-Forwarded-Hostis only honored from a trusted proxy. The same-origin guard used to accept a forwarded host from any direct client, letting a caller promote its own header into the trusted-origin set. The forwarded host now counts only when the immediate peer passes the operator'sTRUST_PROXYsetting — deployments behind a reverse proxy should confirmTRUST_PROXYis configured, or the proxy's forwarded host is ignored in favor of the rawHostheader. (#12832)templateIderror) — existing unsupported connections now receive an accurate rejection. (#13346)Highlights
gh, and GitHub tools resolve to the responsible person's credentials per accepted instruction — with durable continuation rules and no fallback to a teammate's access (#13005), and that identity projects into sandbox runners too (#12907). Around the core: browse repository access across organizations (#12998), select multiple source repositories per project (#13010), duplicate connections to the same GitHub account resolve cleanly (#13022), and sign-in state and connected-repository access are visible and simplified in the UI (#12993, #13047, #12893).Improvements
enableNativeRunnerflag, which now defaults to on for self-hosted instances (cloud-managed instances keep it off) (#13068): native Codex execution and a Claude ACPX runtime plus a qualified OpenCode runtime (#12616, #12590, #12588, #12691), managed provider backends (#12699), a remote execution substrate with secure transport (#12638, #12639), administration and observability (#12641), and native turns projected into task chat (#12617). The control is one unified flag that gates every setup path (#12656, #12666). The open default only unlocks the gate: explicitly configured local Codex, OpenCode, and qualified ACPX agents can use the runner, onboarding stays on legacy adapters, nothing switches automatically, and turningenableNativeRunneroff in experimental settings closes it again.enableIsolatedWorkspacesByDefault, makes every project without its own policy use isolated per-task git worktrees, so a fleet default no longer means editing each project by hand (#13444). New standard-trust agents can hire other agents by default — low-trust agents keep the disabled default (#12814). Sentry monitoring splits intoSENTRY_DSN_FRONTENDandSENTRY_DSN_BACKENDwith the oldSENTRY_DSNstill working as a fallback (#12678). The experimental settings page sheds dead controls and groups developer tools (#12681), andPAPERCLIP_HIDDEN_SETTINGSis honored in the production switcher menu too (#12788).viewer=fulldocument deep link opens the maximized side pane straight from an external notification (#12812), the composer gains a Stop control with simplified task controls, status badges, and inline blocker removal (#13104, #13097), single-choice questions advance on selection (#13234), runner activity condenses into rolling per-group summaries shared across live and saved views (#13255, #13274, #13421), tasks created from a task are shown by project (#13241), long task chats stay responsive during streaming (#13229, #13228), and mobile gets real entity-picker sheets, full-width task trees, and spacing passes (#13343, #13250, #13304, #13122).test-driveCLI command boots an isolated instance with its own data directory and a provider-backed CEO, with reuse safeguards and restored credential inputs (#12894, #12898); server startup no longer opens a browser unless explicitly asked (#12435).Fixes
listCommentsno longer 500s on a non-UUIDafterCommentId(#8695, @Maxxsong7), and the Docker quickstart passesPAPERCLIP_ALLOWED_HOSTNAMESthrough (#6846, @rsclafani).Upgrade Guide
0231through0279). They run automatically on startup. By train: cleanup of redundant auto-created app-connection tool-profile rows (0231), connection grants and delegated identities (0232), managed external MCP connectors (0233), native-runner provider traces, run-event uniqueness, backends, session recovery, and session goals (0234–0235,0237–0238,0248), removal of stored cheap-model profiles (0236), durable GitHub identities and per-person execution identity contexts (0239–0245), connecting services and reviewing connection actions from tasks (0246–0247,0249), durable task recovery (0250–0254), the chat provider and data foundation (0255–0270), per-agent Codex login bindings (0271), AgentMail inboxes (0272), deployment-safe starting runs (0273), agent chat (0274), iMessage Photon (0275), AI connection and per-user provider defaults (0276–0277), and announcement dismissal state (0278–0279). Only0231and0236discard data — redundant tool-profile include rows and the removed cheap-model profiles respectively; everything else is additive.SENTRY_DSN_FRONTEND/SENTRY_DSN_BACKEND— separate browser and server error monitoring; the legacySENTRY_DSNstill works as a fallback for either. (#12678)PAPERCLIP_ANNOUNCEMENTS_ENABLED— in-app announcements are on by default; set tofalseto opt out.PAPERCLIP_ANNOUNCEMENTS_FEED_URLoverrides the feed (defaulthttps://pages.paperclip.ing/announcements/v1/current.json). (#13403)PAPERCLIP_TOKEN_BROKER_ALLOWED_HOSTS— comma-separated extra hosts the sandbox token broker may reach, for remote MCP setups (default: none). (#12339)PAPERCLIP_DISABLE_CWD_ENV_FILE— set totrueto stop the server from loading a.envfile from its working directory (default: it loads). (#12894)modelProfilesis gone from adapter metadata, agent runtime configuration, and task overrides (#12683); plaintextenvvalues in agent responses are redacted (#9860); Anthropic's legacy REST connection setup option is removed (#13346).enableNativeRunnernow defaults to on for self-hosted instances — explicitly configured agents only, nothing switches automatically, cloud-managed instances stay off (#13068); new standard-trust agents can hire other agents by default (#12814), unset Claude models resolve to Opus 5 (#13055), Apps is no longer behind an experimental gate (#12728), andX-Forwarded-Hostrequires proxy trust (see Breaking Changes).Contributors
This release has 503 commits from 15 contributors. Thank you to everyone who contributed to this release!
@aaymeloglu, @glovario, @im0xMagnus, @lorenzozane, @Maxxsong7, @melbinjp, @rsclafani, @stubbi, @zannis
Configuration
📅 Schedule: (in timezone Europe/Madrid)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.