Commit graph

11404 commits

Author SHA1 Message Date
pulse-triage[bot]
702278cd8c Merge reviewed candidate 20260922T162030Z-core-runtime
Integrate the exact reviewed #2076 mixed-source disk correlation repair and regression coverage.

Change-source: pulse-maintainer
2026-09-22 18:14:11 +01:00
pulse-triage[bot]
ddf87b5672 Merge reviewed candidate 20260922T162021Z-web-product
Integrate the exact reviewed #2123 single-line bootstrap repair and its retained browser/source proof.

Change-source: pulse-maintainer
2026-09-22 18:14:10 +01:00
pulse-triage[bot]
994ffd16fe Merge upstream main before publication
Change-source: pulse-maintainer
2026-09-22 17:40:19 +01:00
pulse-triage[bot]
a0861d5f66 chore(frontend): bind install paste proof to tested candidate
The test-only assertion update preserves the browser-tested runtime bytes. Bind the retained content-matching receipt to the completed source-proof candidate.

Change-source: pulse-maintainer
2026-09-22 17:32:16 +01:00
pulse-triage[bot]
4f3734630f test(agents): expect single-line installer option separators
Update the existing extra-argument ordering assertion to the repaired single-line grammar. The exact-source run passed the new paste and execution regressions but exposed this obsolete multiline formatting expectation.

Change-source: pulse-maintainer
2026-09-22 17:29:32 +01:00
pulse-triage[bot]
064b28367a fix(resources): correlate linked disks with missing hardware IDs
Resolve issue #2076 mixed PVE/agent aliases only within the same parent and unique compatible device topology. Reject conflicting populated identities and controller-member fallback; preserve usable serials and WWNs over placeholders. Include snapshot and JSON regression coverage in the canonical registry verification artifact.

Change-source: pulse-maintainer
2026-09-22 17:27:50 +01:00
pulse-triage[bot]
097e3386e0 fix(agents): keep copied Unix install commands single-line safe
Use explicit shell separators instead of newline-dependent grammar for command fields. Preserve quoted values, private token files, TLS options and preflight ordering; cover paste normalization and execution failures in the owning regression suite. Refs #2123.

Change-source: pulse-maintainer
2026-09-22 17:27:29 +01:00
pulse-triage[bot]
65c5630eb5
Merge pull request #2162 from rcourtman/maintainer/20260922T153254Z
Make guest filesystem mount paths readable
2026-09-22 16:20:54 +00:00
pulse-triage[bot]
9fbc4e7b3a fix(notifications): persist and group resolved alert deliveries
Prevent simultaneous recoveries from bypassing the configured grouping window. Preserve destination receipts and pending restart recovery, and keep PagerDuty incident keys separate. Include the notification contract and regression coverage with the runtime change.

Change-source: pulse-maintainer
2026-09-22 16:52:29 +01:00
pulse-triage[bot]
e8383ed63f chore(frontend): bind browser proof to integrated candidate
The integration merge preserves the exact browser-tested frontend bytes. Rebind the content-bound receipt to that merge so the canonical range passes the parent-identity guard.

Change-source: pulse-maintainer
2026-09-22 16:15:05 +01:00
pulse-triage[bot]
4b1fb511d1 Merge reviewed candidate 20260922T131605Z-web-product (pulse da19341fcd)
Change-source: pulse-maintainer
2026-09-22 16:14:24 +01:00
pulse-triage[bot]
a4efb83c1e Merge upstream main before candidate integration
Change-source: pulse-maintainer
2026-09-22 16:14:23 +01:00
pulse-triage[bot]
da19341fcd fix(web): keep guest filesystem mount paths readable
Render complete wrapping paths above usage using an opt-in shared detail-row layout. Preserve compact rows and unknown-usage semantics. Include the typed regression fixture, registered primitive and Workloads guardrails, substantive owning contracts and the content-bound five-layout browser receipt in the same candidate commit. Recompose the rejected unshared candidate without changing its browser-tested runtime bytes. Addresses #2121.

Change-source: pulse-maintainer
2026-09-22 14:42:22 +01:00
pulse-triage[bot]
c40aa70f04
Merge pull request #2159 from rcourtman/maintainer/20260922T124446Z
Expand PBS History refresh coverage across reported host layouts
2026-09-22 13:25:27 +00:00
pulse-triage[bot]
cc1dca44d0 test(resources): cover PBS metrics target continuity across refreshes
Exercise in-memory snapshot replacement, cached lookup and unified reseeding for PBS-only, agent and side-by-side PVE hosts. Verify label, order and freshness changes do not replace history coordinates, while actual agent removal or replacement does not pin stale targets.

Change-source: pulse-maintainer
2026-09-22 14:04:18 +01:00
pulse-triage[bot]
da1dddc1af test(web): cover PBS host topologies across automatic refresh
Extend the PBS History regression to PBS-only and bare-metal PVE/PBS host shapes, stable and reordered snapshots, and desktop/mobile widths. Retain guest coverage and assert drawer identity, tab selection and history targets. This does not claim the separate reported tab reset is reproduced or resolved.

Change-source: pulse-maintainer
2026-09-22 13:07:13 +01:00
pulse-triage[bot]
f91ef61a53
Merge pull request #2156 from rcourtman/maintainer/20260922T112213Z
Keep PBS datastore History attached during refresh
2026-09-22 11:49:06 +00:00
pulse-triage[bot]
dab8daa9a7 fix(web): preserve PBS datastore identity across snapshot reordering
Detach each rendered datastore from the nested PBS snapshot so independent row reconciliation cannot overwrite another datastore's identity. Cover switching and refreshed History in the component regression and real-browser fixture for #1723.

Contract-Neutral: Restore existing PBS datastore row identity during snapshot reconciliation; no API or canonical ownership change.
Change-source: pulse-maintainer
2026-09-22 12:11:59 +01:00
pulse-triage[bot]
014190ea4c
Merge pull request #2154 from rcourtman/maintainer/20260922T092954Z
Fix PBS host history correlation and alert-card footer alignment
2026-09-22 10:50:32 +00:00
pulse-triage[bot]
9d6025d386 style(frontend): format the PBS host-history regression test
Prettier wraps the added byAgentKey assertion, which failed the Frontend format:check on the candidate integration pull request. Re-point the browser receipt base at this commit's parent; the cumulative guard compares the receipt at the tip against the tip parent, and the two user-visible frontend sources are unchanged.

Change-source: pulse-maintainer
2026-09-22 10:49:25 +01:00
pulse-triage[bot]
76f96f9906 chore(frontend): refresh browser receipt base to the integration merge
The cumulative browser guard matches the receipt at the integration tip against the tip parent. Re-point base_sha from the candidate tip parent e9a426aeeb to the integration merge a3ad75e78b so the content-addressed receipt for the two frontend sources is accepted.

Change-source: pulse-maintainer
2026-09-22 10:28:06 +01:00
pulse-triage[bot]
a3ad75e78b Merge reviewed candidate 20260922T083537Z-web-product (pulse 98cab1a8bd)
Integrates the web-product candidate: #2119 alert-card footer alignment (41fa79d52b) and #1723 PBS host-history correlation across guest and agent rows (e9a426aeeb), with the cumulative browser receipt at 98cab1a8bd. Preflight passed; base efeac6cb72.

Change-source: pulse-maintainer
2026-09-22 10:27:48 +01:00
pulse-triage[bot]
e4382af24f
Merge pull request #2152 from rcourtman/maintainer/20260922T082007Z
Some checks are pending
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Fix spurious PBS backup alerts and Proxmox LXC memory; qualify release-line RCs
2026-09-22 08:51:44 +00:00
pulse-triage[bot]
98cab1a8bd test(frontend): rebind the candidate browser receipt to both surfaces
The cumulative candidate browser guard compares the receipt at the tip against every user-visible frontend source changed since the candidate base. This candidate carries two: the #2119 alert-card footer class and the #1723 PBS host-history correlation. Record both content-addressed sources, the union of the two offline proof matrices, and re-point base_sha at the tip parent so the guard can match the candidate.

Change-source: pulse-maintainer
2026-09-22 09:49:38 +01:00
pulse-triage[bot]
e9a426aeeb fix(web): correlate PBS host history across guest and agent rows (#1723)
A standalone source=pbs host row and the PVE guest carrying the same agent are one machine. Collapse correlation candidates that share an agent identity and prefer the guest metrics target, whose persisted host series the Backups drawer renders; the PBS service target names the service key and has no host history. Distinct agent identities, or rows without a provable identity, still decline to choose so the drawer cannot substitute an unrelated host. Re-compose the reviewed runtime change with its three subsystem contracts, offline browser fixture, check script and a content-addressed browser receipt in one governed commit.

Change-source: pulse-maintainer
2026-09-22 09:43:00 +01:00
pulse-triage[bot]
c3213510e6 Merge the #2119 alert-card footer repair (41fa79d52b)
Change-source: pulse-maintainer
2026-09-22 09:42:04 +01:00
pulse-triage[bot]
d6e79593ec
Merge pull request #2151 from rcourtman/dependabot/docker_compose/tests/integration/alpine-3.24
Bump alpine from 3.24 to 3.24 in /tests/integration
2026-09-22 09:38:18 +01:00
pulse-triage[bot]
efeac6cb72 Merge reviewed candidate 20260922T074002Z-delivery-trust (pulse d5de3e26fc)
Change-source: pulse-maintainer
2026-09-22 09:12:22 +01:00
pulse-triage[bot]
e9ace60929 chore(governance): register the #2148 LXC memory completion pair
Register 8b56fc72e4 with its contract-completion commit so canonical governance evaluates the reviewed Proxmox LXC linked-agent memory runtime change and its monitoring and unified-resources contract sections as one historical unit.

Change-source: pulse-maintainer
2026-09-22 08:46:39 +01:00
pulse-triage[bot]
1026f5293b docs(monitoring): record #2148 LXC linked-agent-memory contracts
Complete the #2148 runtime change with the monitoring and unified-resources contract sections its canonical subsystem paths require, so the combined change satisfies the canonical completion guard without rewriting reviewed history.

Change-source: pulse-maintainer
2026-09-22 08:46:29 +01:00
pulse-triage[bot]
bf3fecc16d Merge commit '8b56fc72e4' into maintainer-async/20260922T074019Z-core-runtime/pulse
Change-source: pulse-maintainer
2026-09-22 08:46:14 +01:00
pulse-triage[bot]
50405af743 fix(alerts): skip backup-age alerts for PBS host backups (#2136)
A PBS host/config backup (backup-type host) is keyed by the node name, not a guest VMID, so CheckBackupsWithInventory raised a guest backup-age alert under a node-named subject (for example 'nas backup via proxmox-pbs') that never advanced while the node's guests were backed up, notifying repeatedly. Skip backup-age alerts for PBS subjects with no guest VMID: they are host/config backups, not guest workloads, and the Backups overview already keeps them out of guest coverage. PVE host backups already produce no subject and no alert, restoring consistency. Genuine orphaned PBS guest backups (numeric VMID) and PMG node backups still alert. The recovery point and rollup are retained, so inventory and artifact display are unchanged; only the spurious alert is cleared. Includes the alerts subsystem contract record and the regression tests.

Change-source: pulse-maintainer
2026-09-22 08:01:27 +01:00
dependabot[bot]
fb73cce5c1
Bump alpine from 3.24 to 3.24 in /tests/integration
Bumps alpine from 3.24 to 3.24.

---
updated-dependencies:
- dependency-name: alpine
  dependency-version: '3.24'
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-22 03:43:48 +00:00
pulse-triage[bot]
d5de3e26fc fix(release-control): qualify release-line RCs against their own branch
The secure-runtime RC qualification workflow (commit 79d87a4a2c) resolves the branch the control plane maps the version to and passes it as --main-ref, but secure_runtime_attestation_v6.verify_canonical_main_identity still required origin/main and required the candidate to be an ancestor of origin/main. Every release-train candidate therefore failed the pre-authentication step before any check ran; v6.4.5-rc.1 failed at 'Pre-authenticate exact qualification packet' with 'committed-main classification requires canonical origin/main' (run 35680955017), and all three historical runs failed.

Accept exactly origin/main or the release train's origin/release/vX.Y, verify the ref against the canonical origin's live branch tip, and check candidate ancestry against that same ref. The release-candidate classification is unchanged. Update the deployment-installability contract and the v6 unit tests, including a mapped-release-branch acceptance case.

Change-source: pulse-maintainer
2026-09-22 04:28:39 +01:00
pulse-triage[bot]
8b56fc72e4 fix(monitoring): prefer linked agent memory for Proxmox LXC
Extend the #1962 linked-agent memory fallback to Proxmox LXC containers (#2148). A correlated online Pulse agent running inside a container now supplies the container's memory metric instead of the cache-inclusive cluster/resources fallback, which can badly under-report shared-memory workloads. The agent sample is only trusted when its total matches the container's configured limit, so an agent without lxcfs cannot leak host memory into the guest row. Threads the previous-guest agent map through the efficient and node-by-node container builders and reads agent-owned memory from merged ContainerView resources.

Change-source: pulse-maintainer
2026-09-21 23:24:33 +01:00
rcourtman
dd93eeb6b4
Merge pull request #2147 from rcourtman/fix/patrol-objective-recovery
Some checks failed
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Patrol Qualification Regression / Catalog, scorer, and replay regression (push) Has been cancelled
Recover saved Patrol objectives without observers
2026-09-21 17:50:27 +01:00
rcourtman
2856bd16b3 Recover saved Patrol objectives without observers
Saved objectives could remain uncovered indefinitely after their in-memory
setup trigger was lost or rejected. Reconcile missing or invalidated
observers from retained intent and recheck its revision at run admission.

Persist attempt timing before provider work so restart and history pruning
cannot erase pacing. Keep coverage dependent on actual observer validation,
installation and health evidence.

Support case patrol-objective-recovery.
2026-09-21 17:18:32 +01:00
pulse-triage[bot]
41fa79d52b fix(alerts): align the Started run with the alert-card footer (#2119)
The Alerts overview alert-card footer is an items-center flex row whose first child, the Started timestamp, carried its own mt-1. Under items-center that margin shifted the Started run 2px below the adjacent delivery-status run, which is the small text misalignment the reporter underlined in #2119. Remove the child margin; the footer row already carries the top margin, so the two runs share a baseline.

Add a presentation regression test and an offline browser proof that measures the text rects of both runs at desktop and narrow widths.

Contract-Neutral: Behavioral footer-alignment fix; no public-contract or subsystem-shape delta.
Change-source: pulse-maintainer
2026-09-21 14:31:27 +01:00
pulse-triage[bot]
eb47a4e653
Merge pull request #2144 from rcourtman/maintainer/20260921T112617Z
Some checks are pending
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Patrol Qualification Regression / Catalog, scorer, and replay regression (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Unified Agent Native Verification / Linux ARM64 (push) Waiting to run
Unified Agent Native Verification / Linux x64 (push) Waiting to run
Unified Agent Native Verification / Windows x64 (push) Waiting to run
Unified Agent Native Verification / macOS ARM64 (push) Waiting to run
Unified Agent Native Verification / macOS Intel (push) Waiting to run
Unified Agent Native Verification / FreeBSD cross-build contract (push) Waiting to run
Fix node Verify SSL setting reverting after re-registration (#2140)
2026-09-21 12:14:14 +00:00
pulse-triage[bot]
adc68cb7a6 Merge reviewed candidate 20260921T104103Z-core-runtime (pulse 10d672c5fa)
Preserve an operator's Verify SSL choice across PVE consolidation and canonical auto-registration (#2140).

Change-source: pulse-maintainer
2026-09-21 12:23:57 +01:00
pulse-triage[bot]
10d672c5fa chore(release-control): register #2140 completion pairs
Register the two #2140 runtime commits with their contract and proof completion commit so the canonical completion guard evaluates each runtime change together with the follow-up that records its contracts and verification artifacts, as one reviewed unit. Registry-only change; no runtime behaviour.

Change-source: pulse-maintainer
2026-09-21 11:55:03 +01:00
pulse-triage[bot]
9fa81dee8f docs(release-control): complete #2140 TLS-preservation contracts
Record the #2140 node TLS-preference fix in the contracts its runtime commits touch: agent-lifecycle, api-contracts, security-privacy and the dependent storage-recovery contract, with the node API payload and persisted-field proofs in internal/api/contract_test.go and internal/config/config_load_test.go. The canonical completion history registers these contract and proof files as the completion of the auto-register and consolidation runtime commits.

Change-source: pulse-maintainer
2026-09-21 11:54:39 +01:00
pulse-triage[bot]
fd00e62cde
Merge pull request #2141 from rcourtman/maintainer/20260921T100425Z
Ship reviewed frontend dependency security updates
2026-09-21 10:49:03 +00:00
pulse-triage[bot]
919009d767 fix(config): honour explicit operator VerifySSL across PVE merge
ConsolidatePVEInstances promoted VerifySSL false->true whenever a merged duplicate or standalone had it enabled, silently re-enabling a disabled Verify SSL certificate setting on every save, load and monitor reconciliation (#2140). The add and update handlers now record an explicit operator choice in VerifySSLExplicit; a merge never overrides it, while the historical promotion is kept when neither side recorded a choice so an existing secure connection is not downgraded. A merged fingerprint still pins the peer.

Regression tests cover the standalone and duplicate-cluster merges and the reported PUT-save path through normalizePVEConfigState.

Change-source: pulse-maintainer
2026-09-21 11:47:26 +01:00
pulse-triage[bot]
10ad85e0cf fix(config): keep operator VerifySSL across PVE consolidation
ConsolidatePVEInstances promoted VerifySSL false->true when folding a duplicate cluster or overlapping standalone into the canonical instance, silently re-enabling a disabled Verify SSL certificate setting on every save, load and monitor reconciliation (#2140). The canonical instance now owns the preference; a merged fingerprint still pins the peer, so verification is not downgraded.

Regression tests cover the standalone and duplicate-cluster merges and the reported PUT-save path through normalizePVEConfigState.

Change-source: pulse-maintainer
2026-09-21 11:43:51 +01:00
pulse-triage[bot]
a211d2ea17 docs(release-control): complete #2140 TLS-preservation contracts
Record the canonical-shape completion for the auto-register VerifySSL preservation in the agent-lifecycle contract and its api-contracts and storage-recovery dependents, so the runtime change is documented in the same candidate.

Change-source: pulse-maintainer
2026-09-21 11:38:14 +01:00
pulse-triage[bot]
529e815525 fix(configapi): preserve operator VerifySSL on auto-register
Re-registration of an existing node overwrote the stored VerifySSL value with the fingerprint-capture result, silently re-enabling a disabled Verify SSL certificate setting on every agent health-check repair (#2140). Preserve the operator's choice and keep only the legacy heal where strict verification is on with no pin (#1303).

Change-source: pulse-maintainer
2026-09-21 11:26:23 +01:00
pulse-triage[bot]
c008d33d40 test(configapi): probe verifySSL persistence for #2140
Reproduction probe for the reported SSL toggle not sticking.

Change-source: pulse-maintainer
2026-09-21 11:23:56 +01:00
pulse-triage[bot]
624221e10a build(frontend): land the reviewed npm-minor-patch security floors
Dependabot's npm-minor-patch group (#2138) bumps frontend-modern and tests/integration but is blocked by Canonical Governance, which requires the deployment-installability contract update and the frontend dependency security proof in the same commit. The portal frontend in the same group is split out: it needs a portal bundle rebuild and is owned separately.

Carry the frontend-modern manifest/lock bump (dompurify 3.4.15, highlight.js 11.12.0, solid-js 1.9.15, @types/node 26.6.1, typescript-eslint 8.70.0, autoprefixer 10.6.1, eslint-plugin-solid 0.18.0, postcss 8.5.28, prettier 3.9.8, vite-plugin-solid 2.11.14, vite-plugin-sri-gen 1.7.4) and the tests/integration @types/node 26.6.1 bump with a Current State contract entry and dependencySecurity floor assertions. @playwright/test stays pinned at 1.56.1, so browser-test parity is unchanged.

Change-source: pulse-maintainer
2026-09-21 10:44:34 +01:00
pulse-triage[bot]
a7da26e8ba Merge origin/main into the reviewed maintenance line
Change-source: pulse-maintainer
2026-09-21 10:29:15 +01:00