* chore(deps): refresh dependencies with a seven-day cutoff
* fix(deps): preserve Teams and jsdom integration contracts
Use the Teams SDK public token and processing APIs while keeping SSO sender
checks ahead of native token operations. Remove obsolete ambient declarations
and route workarounds, and cover the SDK routing with real processing tests.
Adapt the test environment to jsdom private-field bindings, preserve file bytes
and registry cleanup, and preload it through native Node and Bun workers.
* fix(test): preserve jsdom window and fixture contracts
* fix(ci): keep typecheck cache reuse within matching inputs
* fix(perf): isolate benchmark subprocess transport
Run transported CLI samples and their temporary state through the explicit SUT transport while preserving native measurements. Reject unsupported transported runtime RSS and profiles before launching candidate code.
Punchcard-Session: coral-orchard-orchard-d4
* fix(perf): isolate external evaluator from candidate runtime
Add the standalone off-Actions harness with separate runner and candidate identities, bounded collection, and preserved workload receipts. Retain custom evaluator diagnostics without granting gate authority; leave workflow activation to the dependent change.
Punchcard-Session: coral-orchard-orchard-d4
* fix(perf): reject mixed benchmark execution modes
Record evaluator-owned execution identity per suite and enforce compatible modes in comparisons, budget checks, and source summaries while preserving independent RSS semantics.
Punchcard-Session: coral-orchard-orchard-d4
* fix(perf): retain receipts after custom diagnostic failures
Capture the complete custom collection, validation, and summary phase without disabling errexit. Preserve workload failure precedence and always reach the separate sealed-export and receipt finalizer.
Punchcard-Session: coral-orchard-orchard-d4
* test(ci): preserve fixed IMDS probe argument tuples
Punchcard-Session: coral-orchard-orchard-d4