Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
1b59500
Move Redis/RabbitMQ/Container Manager to developer-desktop-util-plugin
claude Sep 15, 2026
4b401eb
Make the MCP tool catalogue plugin-driven instead of hardcoded
claude Sep 15, 2026
5ad6ba2
Move Kafka Explorer to developer-desktop-util-plugin
claude Sep 15, 2026
30c707c
Merge pull request #117 from DianaSensei/claude/desktop-utils-plugin-…
DianaSensei Sep 16, 2026
ff844df
Auto-check for plugin/service updates, badge, and clean up old versio…
DianaSensei Sep 16, 2026
c791f4b
Fix Coverage and Security CI: missing sidecar placeholders, rustls ad…
DianaSensei Sep 16, 2026
0bf8533
Bump vitest and @vitest/coverage-v8 to 5.0.0 together (#124)
DianaSensei Sep 16, 2026
6e4956d
Add devtool://install deep link for one-click plugin install (#126)
DianaSensei Sep 16, 2026
30b60bc
Repo cleanup: data-loss races, atomic writes, context re-render fixes…
DianaSensei Sep 16, 2026
e09de91
Add CHANGELOG.md: note Redis/RabbitMQ/Container/Kafka moved to plugin…
DianaSensei Sep 16, 2026
6be3a19
Retire the canary release channel — new architecture is now stable on…
DianaSensei Sep 16, 2026
fa047bd
Allow release.yml to run via workflow_dispatch too (#130)
DianaSensei Sep 16, 2026
b3d1257
Fix release.yml: v0.9.0 published with no Windows installers (#131)
DianaSensei Sep 16, 2026
eb161ac
Split release.yml into build-then-publish: tag only after every platf…
DianaSensei Sep 16, 2026
efa3661
Fix build-updater-manifest.mjs: bundle output is nested one level per…
claude Sep 16, 2026
70bf790
Make the release a draft until every publish step succeeds
claude Sep 16, 2026
6dced34
Merge pull request #133 from DianaSensei/fix-updater-manifest-nested-…
DianaSensei Sep 16, 2026
e250ecc
Fix build-updater-manifest.mjs: GET /releases/tags/{tag} 404s on a draft
claude Sep 16, 2026
047db44
Merge pull request #134 from DianaSensei/fix-manifest-draft-release-l…
DianaSensei Sep 16, 2026
bf2112a
Fix build-updater-manifest.mjs: GET /releases blew execFileSync's max…
claude Sep 16, 2026
0517136
Merge pull request #135 from DianaSensei/fix-manifest-releases-list-e…
DianaSensei Sep 16, 2026
6e61fa4
Dedupe Node/Rust/cache/system-deps setup into a shared composite action
claude Sep 16, 2026
48cd9fc
Add --ignore-scripts to npm ci (SonarCloud finding from PR #136)
claude Sep 16, 2026
869c4fd
Merge pull request #137 from DianaSensei/fix-npm-ci-ignore-scripts
DianaSensei Sep 16, 2026
0a2e7f7
build(deps): bump rmcp from 1.8.0 to 3.4.0 in /src-tauri (#125)
DianaSensei Sep 16, 2026
c1b9ea9
build(deps): bump the minor-and-patch group across 1 directory with 2…
dependabot[bot] Sep 16, 2026
af3cc9c
build(deps): bump the minor-and-patch group across 1 directory with 9…
dependabot[bot] Sep 16, 2026
37f4629
build(deps): bump github/codeql-action/upload-sarif (#113)
dependabot[bot] Sep 16, 2026
a0c89fe
build(deps): bump actions/checkout from 6 to 7 (#118)
dependabot[bot] Sep 16, 2026
6ae6d22
build(deps): bump taiki-e/install-action from 2.87.5 to 2.87.12 (#119)
dependabot[bot] Sep 16, 2026
3a8e9a4
Fix build-updater-manifest.mjs: signature field was double base64-enc…
claude Sep 16, 2026
175e146
Merge pull request #138 from DianaSensei/fix-updater-manifest-double-…
DianaSensei Sep 16, 2026
f77cd23
Pin pullfrog.yml's actions to commit SHAs (Security pipeline was fail…
claude Sep 16, 2026
1c1bbde
Merge pull request #139 from DianaSensei/fix-pullfrog-unpinned-actions
DianaSensei Sep 16, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
75 changes: 75 additions & 0 deletions .github/actions/setup-tauri-env/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,75 @@
name: 'Setup Tauri build environment'
description: >
Node, Rust, the Rust build cache, and (on Linux) Tauri's system deps —
the same five steps release.yml, build-cache.yml, and coverage.yml each
used to repeat with identical bodies, kept in one place so pinned action
SHAs and the apt package list only need updating once.

inputs:
rust-target:
description: 'Extra Rust target to install (matrix.rust-target), or empty for the host target'
default: ''
rust-components:
description: 'Comma-separated rustup components, e.g. llvm-tools-preview'
default: ''
cache-shared-key:
description: 'Swatinem/rust-cache shared-key — must match between the job that saves and the job(s) that restore'
required: true
cache-save-if:
description: >
Swatinem/rust-cache save-if. Restore-only jobs (release.yml's tag
builds) pass 'false' — the cache is refreshed on main by
build-cache.yml instead, so a tag run saving its own copy would
never be reused by any other tag.
default: 'true'
install-frontend-deps:
description: "Run 'npm ci'. Set to 'false' if the caller needs Rust/cache only."
default: 'true'

runs:
using: composite
steps:
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: lts/*
cache: npm

- name: Install Rust stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable branch
with:
toolchain: stable
targets: ${{ inputs.rust-target }}
components: ${{ inputs.rust-components }}

- name: Cache Rust build artifacts
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
workspaces: src-tauri -> target
cache-on-failure: true
shared-key: ${{ inputs.cache-shared-key }}
save-if: ${{ inputs.cache-save-if }}

- name: Install Linux system dependencies
if: runner.os == 'Linux'
shell: bash
run: |
sudo apt-get update
sudo apt-get install -y \
libwebkit2gtk-4.1-dev \
libjavascriptcoregtk-4.1-dev \
libappindicator3-dev \
librsvg2-dev \
patchelf

# --ignore-scripts: SonarCloud flagged the bare `npm ci` (S4830-class —
# "package manager scripts should not be executed during installation").
# Safe here: package-lock.json's only `hasInstallScript` entry is
# fsevents, an optional macOS-only file watcher used by `npm run dev`
# — nothing this repo's CI (build/lint/test) ever touches. Verified
# `npm ci --ignore-scripts` still installs cleanly and `tsc --noEmit`
# still passes.
- name: Install frontend dependencies
if: inputs.install-frontend-deps == 'true'
shell: bash
run: npm ci --prefer-offline --no-audit --no-fund --ignore-scripts
31 changes: 9 additions & 22 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,30 +26,17 @@ updates:
open-pull-requests-limit: 5

# The docker-compose test fixtures under testing/ are not shipped in the app,
# but they are still code in this repo and they still go stale. Without these
# entries only npm and cargo were kept current, and the Spring fixture sat a
# year behind its parent BOM until a security alert surfaced it. Dependabot
# security alerts fire for every detected manifest regardless of this file —
# version updates do not, which is the gap these close.
- package-ecosystem: maven
directory: /testing/rabbitmq/spring-rpc
schedule:
interval: weekly
open-pull-requests-limit: 5
groups:
minor-and-patch:
update-types: [minor, patch]

# Both requirements.txt files are pinned with --require-hashes; Dependabot
# regenerates the hashes along with the version.
# but they are still code in this repo and they still go stale. Without this
# entry only npm and cargo were kept current. Dependabot security alerts fire
# for every detected manifest regardless of this file — version updates do
# not, which is the gap this closes.
#
# testing/rabbitmq (and its spring-rpc fixture) moved to
# developer-desktop-util-plugin along with the RabbitMQ plugin — see
# docs/decisions/architecture/platform-plugin-architecture.md. Configure
# dependabot there instead.
Comment on lines +34 to +37

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The comment above says to configure Dependabot in the plugin repo, but the pip entry just below still targets /testing/kafka — a directory this PR deletes. Dependabot will fail to find that manifest on each run (and the RabbitMQ maven entry was removed, so this is the one leftover).

- package-ecosystem: pip
directory: /testing/kafka
schedule:
interval: weekly
open-pull-requests-limit: 5

- package-ecosystem: pip
directory: /testing/rabbitmq
schedule:
interval: weekly
open-pull-requests-limit: 5
41 changes: 8 additions & 33 deletions .github/workflows/build-cache.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,40 +45,15 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
# Setup shared with release.yml/coverage.yml — see
# .github/actions/setup-tauri-env. Same shared-key as release.yml so
# the cache this saves is the exact cache the tag release restores
# (default cache-save-if: 'true' — this is the job that refreshes it).
- name: Setup build environment
uses: ./.github/actions/setup-tauri-env
with:
node-version: lts/*
cache: npm

- name: Install Rust stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable branch
with:
toolchain: stable
targets: ${{ matrix.rust-target }}

# Same shared-key as release.yml so the cache this saves is the exact cache
# the tag release restores. Saves on this run (main scope).
- name: Cache Rust build artifacts
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
workspaces: src-tauri -> target
cache-on-failure: true
shared-key: ${{ matrix.platform }}-${{ matrix.rust-target }}

- name: Install Linux system dependencies
if: matrix.platform == 'ubuntu-22.04'
run: |
sudo apt-get update
sudo apt-get install -y \
libwebkit2gtk-4.1-dev \
libjavascriptcoregtk-4.1-dev \
libappindicator3-dev \
librsvg2-dev \
patchelf

- name: Install frontend dependencies
run: npm ci
rust-target: ${{ matrix.rust-target }}
cache-shared-key: ${{ matrix.platform }}-${{ matrix.rust-target }}

- name: Build frontend
run: npm run build
Expand Down
68 changes: 30 additions & 38 deletions .github/workflows/coverage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,52 +39,44 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

# The Rust bin crate embeds the frontend via `generate_context!`, which
# reads `frontendDist` (../dist) at compile time. Build the frontend first
# so the crate (and therefore its tests) compiles.
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
# Setup shared with release.yml/build-cache.yml — see
# .github/actions/setup-tauri-env (Node, Rust + llvm-tools-preview,
# Linux system deps, npm ci). GitHub scopes Actions caches per ref: a
# PR can RESTORE the default branch's cache, but a cache it SAVES is
# visible only to that PR branch — saving on every PR would mint
# large, un-shareable, instrumented-build caches that just churn the
# 10 GB limit and evict main's useful one. So only main saves.
- name: Setup build environment
uses: ./.github/actions/setup-tauri-env
with:
node-version: lts/*
cache: npm

- name: Install frontend dependencies
run: npm ci
rust-components: llvm-tools-preview
cache-shared-key: coverage
cache-save-if: ${{ github.ref == 'refs/heads/main' }}

# The Rust bin crate embeds the frontend via `generate_context!`, which
# reads `frontendDist` (../dist) at compile time. Needed before the
# first `cargo`/`cargo llvm-cov` invocation below.
- name: Build frontend (creates ../dist for generate_context!)
run: npm run build

# Tauri's system dependencies — same set the release build uses.
- name: Install Linux system dependencies
# tauri-build's build.rs checks that every `bundle.externalBin` resource
# (tauri.conf.json) exists on disk, even for a plain `cargo test`/`cargo
# llvm-cov` that never bundles anything — normally `beforeBuildCommand`
# (npm run build:mcp-sidecar / build:service-sidecars) produces the real
# binaries, but this job only builds the frontend, so `cargo` fails at
# the very first build-script run with "resource path ... doesn't exist".
# Coverage doesn't run these sidecars, only compiles their crate — empty
# placeholders named exactly like the real target-triple-suffixed
# binaries satisfy the resource check without the cost of a real build.
- name: Placeholder externalBin resources (coverage doesn't run sidecars, just needs them to exist)
run: |
sudo apt-get update
sudo apt-get install -y \
libwebkit2gtk-4.1-dev \
libjavascriptcoregtk-4.1-dev \
libappindicator3-dev \
librsvg2-dev \
patchelf

- name: Install Rust stable
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable branch
with:
toolchain: stable
components: llvm-tools-preview

# GitHub scopes Actions caches per ref: a PR can RESTORE the default
# branch's cache, but a cache it SAVES is visible only to that PR branch
# (never to other PRs or main). Saving on every PR therefore mints large,
# un-shareable, instrumented-build caches that just churn the 10 GB limit
# and evict main's useful one. So only main saves; PRs restore-only.
- name: Cache Rust build artifacts
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
workspaces: src-tauri -> target
shared-key: coverage
save-if: ${{ github.ref == 'refs/heads/main' }}
mkdir -p src-tauri/binaries
triple=$(rustc -vV | sed -n 's/^host: //p')
touch "src-tauri/binaries/devtool-mcp-server-$triple" "src-tauri/binaries/devtool-svc-echo-$triple"
chmod +x src-tauri/binaries/devtool-mcp-server-"$triple" src-tauri/binaries/devtool-svc-echo-"$triple"

- name: Install cargo-llvm-cov
uses: taiki-e/install-action@5bf6ce016fd2e72eefc647cbca1e4213f65955b8 # v2
uses: taiki-e/install-action@3f74d7c16a4242f1c95561e98edc25d36adb4375 # v2
with:
tool: cargo-llvm-cov

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/pullfrog.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,11 +22,11 @@ jobs:
contents: read
steps:
- name: Checkout code
uses: actions/checkout@v6
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
- name: Run agent
uses: pullfrog/pullfrog@v0
uses: pullfrog/pullfrog@4fe55647c66683c209243f2171b013c760d125a7 # v0 (currently v0.1.80)
with:
prompt: ${{ inputs.prompt }}
env:
Expand Down
Loading
Loading