Skip to content

fix(security): upgrade Remix packages 2.1.0 → 2.17.4#3372

Merged
ericallam merged 3 commits intomainfrom
devin/1776162078-remix-upgrade
Apr 15, 2026
Merged

fix(security): upgrade Remix packages 2.1.0 → 2.17.4#3372
ericallam merged 3 commits intomainfrom
devin/1776162078-remix-upgrade

Conversation

@devin-ai-integration
Copy link
Copy Markdown
Contributor

@devin-ai-integration devin-ai-integration Bot commented Apr 14, 2026

Summary

Upgrades all @remix-run/* packages in apps/webapp from 2.1.0 → 2.17.4 to address security vulnerabilities. Recreation of #2951 on a fresh checkout of main.

Updated packages (apps/webapp/package.json):

  • @remix-run/express, @remix-run/node, @remix-run/react, @remix-run/serve, @remix-run/server-runtime: 2.1.0 → 2.17.4
  • @remix-run/router: ^1.15.3 → ^1.23.2
  • @remix-run/dev, @remix-run/eslint-config, @remix-run/testing: 2.1.0 → 2.17.4

Root package.json overrides:

Documentation: Updated Remix version references in CLAUDE.md, apps/webapp/CLAUDE.md, and .cursor/rules/webapp.mdc.

Server changes: Added .server-changes/upgrade-remix-security.md for release tracking per CONTRIBUTING.md.

No application code changes — only package.json files, documentation, a server-changes entry, and the regenerated pnpm-lock.yaml.

Updates since last revision

Addressed all 3 Devin Review findings:

  1. Missing .server-changes/ file — added .server-changes/upgrade-remix-security.md (commit ce22a0b)
  2. Sentry Remix patch (@sentry/[email protected]) — verified the patch at patches/@[email protected] applies cleanly against 2.17.4. The patch modifies Sentry's own RemixInstrumentation wrapper (removing request.clone() and form data attributes), not Remix internals. The underlying Remix APIs it hooks into (callRouteAction, callRouteLoader) are stable across 2.1→2.17.
  3. [email protected] compatibility — peer deps declare @remix-run/react: ^1.16.0 || ^2.0, covering 2.17.4. Confirmed working at runtime across all 22 tested pages that use it (root.tsx, hooks, route loaders).

Verification performed during this session

  • Runtime: Express+Remix integration, magic link login, client-side routing, MetaFunction rendering
  • Operational: hello-world task triggered via API, runs list, run detail, tasks page
  • Comprehensive UI: 22 pages, 11 filter types, environment/project switchers, interactive elements
  • Docker: Production Dockerfile (docker/webapp/Dockerfile) builds successfully
  • Changelog audit: All 16 minor versions reviewed — every breaking change is behind opt-in future flags the webapp doesn't enable

Review & Testing Checklist for Human

  • Verify auth flows in stagingremix-auth, remix-auth-email-link, and remix-auth-github declare peer deps on @remix-run/server-runtime@^1.x, which is now 2.17.4. Login (magic link + OAuth) should be tested in a staging environment since local dev testing may not exercise all auth code paths.
  • Verify tar-fs override versions resolve the targeted security advisories (2.1.4 and 3.1.1)
  • Review new transitive dependencies added by the upgrade: [email protected], [email protected], [email protected], [email protected]

Recommended test plan: deploy to staging and exercise core webapp flows — login (email magic link + GitHub OAuth), dashboard navigation, task triggering/viewing, and API endpoints — to catch runtime regressions not covered by local testing.

Notes

  • Peer dependency warnings for remix-auth-* packages (expecting @remix-run/server-runtime@^1.x) were present in the original PR fix(security): upgrade Remix packages 2.1.0 → 2.17.4 #2951 as well and appear to be pre-existing
  • The lockfile diff is large (~1200 lines) but mechanical — driven by the Remix version bump cascading through transitive dependencies
  • CI failures (audit, units/internal/1-of-8) are unrelated: audit is a claude-code-action bot permissions issue; the internal test failure is a ClickHouse testcontainers Failed to connect to Reaper flake

Link to Devin session: https://app.devin.ai/sessions/d9fa9953b9bf40e5a8d12b8f5ba5b86b
Requested by: @ericallam

devin-ai-integration Bot and others added 2 commits April 14, 2026 10:24
Upgraded packages:
- @remix-run/express: 2.1.0 → 2.17.4
- @remix-run/node: 2.1.0 → 2.17.4
- @remix-run/react: 2.1.0 → 2.17.4
- @remix-run/router: 1.15.3 → 1.23.2
- @remix-run/serve: 2.1.0 → 2.17.4
- @remix-run/server-runtime: 2.1.0 → 2.17.4
- @remix-run/dev: 2.1.0 → 2.17.4
- @remix-run/eslint-config: 2.1.0 → 2.17.4
- @remix-run/testing: 2.1.0 → 2.17.4

Also updated tar-fs override for new @remix-run/dev version.

Co-Authored-By: Eric Allam <[email protected]>
@devin-ai-integration
Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment and CI monitoring

@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented Apr 14, 2026

⚠️ No Changeset found

Latest commit: ce22a0b

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@devin-ai-integration
Copy link
Copy Markdown
Contributor Author

Runtime Test Results — Remix 2.1.0 → 2.17.4

Ran the webapp locally against the upgraded Remix packages, testing core user-facing flows end-to-end.

Test Results (4/4 passed)
Test Result What it proves
Express + Remix integration PASSED createRequestHandler from @remix-run/express serves pages correctly on port 3030
Email magic link login flow PASSED Form, ActionFunctionArgs, authenticator.authenticate, session/cookies, redirect all work
Dashboard client-side routing PASSED @remix-run/react router navigates Tasks → Runs → Env Vars smoothly
MetaFunction page titles PASSED document.title = "Tasks | Trigger.dev" on dashboard
Screenshots

Login page — Express serves Remix app correctly:
Login

Magic link page — Routing and loader work:
Magic link

Dashboard — Full project dashboard loads after login:
Dashboard

Client-side nav — Runs page via sidebar:
Runs

CI Status

34 checks passing, 0 failures. Typecheck, all unit tests (webapp 8/8, internal 8/8, packages 1/1), e2e CLI tests, SDK compat, and CodeQL all green.

Notes
  • Remix 2.17.4 shows deprecation warnings about React Router v7 future flags (v3_fetcherPersist, v3_lazyRouteDiscovery, v3_relativeSplatPath, v3_singleFetch, v3_throwAbortReason). Informational only.
  • No console errors observed during testing.

Devin session

@devin-ai-integration
Copy link
Copy Markdown
Contributor Author

Operational Test Results: Remix 2.17.4 Upgrade

Ran the hello-world reference project's trigger dev server against the local webapp (port 3030) with upgraded Remix packages. Triggered tasks via API and verified key UI pages render correctly.

Devin session

Operational Tests (3/3 passed)
Test Result
Tasks page displays 100+ registered tasks with columns Passed
API trigger creates run, Runs list shows Completed status Passed
Run detail page shows trace tree, logs, timeline, payload/output Passed

Tasks Page

Tasks page loaded with all registered tasks showing Task ID, File path, Running/Queued counts, Activity (7d), Avg. duration columns.

Tasks page

Runs List

Triggered hello-world task via POST /api/v1/tasks/hello-world/trigger. Run completed successfully with 209ms execution time, 7.1s total duration.

Runs list

Run Detail Page

Full trace tree with all spans: onStart()onStartAttempt()run() → log messages (all levels) → traces → wait.for(). Overview panel shows payload {"sleepFor": 1000} and output {"message": "Hello, world!"}.

Run detail

Previous Basic UI Tests (4/4 passed)
Test Result
Express + Remix integration serves pages on port 3030 Passed
Email magic link login flow (Form, action, session, redirect) Passed
Client-side routing between dashboard pages Passed
MetaFunction renders correct page titles Passed

Setup Details

  • Built trigger CLI from source, configured hello-world project to local instance
  • Authenticated CLI against localhost:3030, started dev server (version 20260414.1)
  • All tasks registered successfully from the hello-world reference project

@devin-ai-integration
Copy link
Copy Markdown
Contributor Author

Comprehensive UI Test Results (Phase 3): Every Page, Every Filter, Every Button

Ran the webapp locally (port 3030) with hello-world reference project dev server, triggered 6 diverse tasks (hello-world normal/error, parent-task, batch-task, create-jsonl-file, simple-parent), then systematically tested every page, filter dropdown, and interactive element.

Result: All 30+ tests PASSED

Pages Tested (22 pages)
Page Result Details
Tasks PASSED 100+ tasks listed, search filters correctly
Runs PASSED 7 runs with mixed statuses, all columns render
Run Detail PASSED Full trace tree, logs, timeline, replay button
Batches PASSED Empty state rendered
Schedules PASSED Schedule with CRON, timezone, next run
Queues PASSED Queue list, pagination (9 pages), search, pause
Waitpoint tokens PASSED Empty state with docs links
Deployments PASSED Deploy instructions with env switcher
Test PASSED 100+ tasks with search
Bulk actions PASSED Instructions + "New bulk action" button
API keys PASSED Dev keys section with regenerate
Environment variables PASSED Empty state with "Add new"
Alerts PASSED Dev env message with docs
Preview branches PASSED Empty state with "New branch"
Regions PASSED 400 error (expected - no worker group locally)
Limits PASSED Concurrency, rate limits, quotas, features
Project settings General PASSED Project ref, name form, delete form
Project settings Integrations PASSED Empty content area
Organization settings PASSED Logo, org name form, delete form
Team PASSED User info, invite button, 1 member
Filter Dropdowns Tested
Dropdown Result Details
Filter menu (funnel) PASSED 11 filter types with keyboard shortcuts: Status, Tasks, Tags, Versions, Queues, Machines, Run ID, Batch ID, Schedule ID, Bulk action, Error ID
Status filter PASSED 13 color-coded statuses: Pending version, Delayed, Queued, Dequeued, Executing, Waiting, Completed, Failed, Timed out, Crashed, System failure, Canceled, Expired
Date filter PASSED Custom input, relative presets (1min-30days), exact date range (From/To), quick presets (Yesterday, Today, etc.), Cancel/Apply
Root only toggle PASSED URL updates with ?rootOnly=true

Filter menu (11 types):
Filter menu

Status filter (13 statuses):
Status filter

Switcher Dropdowns Tested
Dropdown Result Details
Environment switcher PASSED Dev (current), Staging, Preview (expandable), Production
Project/Org switcher PASSED Org info, current project (checkmark), New project, New org, Account, Logout

Project/Org switcher:
Project switcher

Interactive Elements Tested
  • Tasks page search: typed "hello", filtered 100+ → 2 matching
  • Run row click: navigated to run detail
  • Root only toggle: URL updated with rootOnly param
  • Sidebar collapse button: accessible
  • Help & Feedback: accessible with 'h' shortcut
  • Manage/Project settings section collapse: works
  • Runs docs external link: present

Conclusion: All pages, filter dropdowns, switchers, and interactive elements work correctly with Remix 2.17.4. No regressions detected. The upgrade is safe.

Devin session

@ericallam ericallam marked this pull request as ready for review April 14, 2026 12:36
devin-ai-integration[bot]

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

@devin-ai-integration devin-ai-integration Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 new potential issues.

View 3 additional findings in Devin Review.

Open in Devin Review

Comment thread apps/webapp/package.json
Comment thread apps/webapp/package.json
@ericallam ericallam merged commit 7d82041 into main Apr 15, 2026
70 of 79 checks passed
@ericallam ericallam deleted the devin/1776162078-remix-upgrade branch April 15, 2026 12:50
@github-actions github-actions Bot mentioned this pull request Apr 17, 2026
ericallam pushed a commit that referenced this pull request May 1, 2026
## Summary
8 new features, 18 improvements, 11 bug fixes.

## Breaking changes
- Add server-side deprecation gate for deploys from v3 CLI versions
(gated by `DEPRECATE_V3_CLI_DEPLOYS_ENABLED`). v4 CLI deploys are
unaffected.
([#3415](#3415))

## Improvements
- Add `--no-browser` flag to `init` and `login` to skip auto-opening the
browser during authentication. Also error loudly when `init` is run
without `--yes` under non-TTY stdin (previously default-and-exited
silently, leaving the project half-initialized). Both commands now show
an `Examples` section in `--help`.
([#3483](#3483))
- Add `isReplay` boolean to the run context (`ctx.run.isReplay`),
derived from the existing `replayedFromTaskRunFriendlyId` database
field. Defaults to `false` for backwards compatibility.
([#3454](#3454))
- Redact the `resolveWaitpoint` runtime log so it only emits `id` and
`type` instead of the full completed waitpoint. Previously the log
printed the entire waitpoint (including `output`) to stdout in
production runs, which could leak sensitive payloads. The value returned
by `wait.forToken()` is unchanged.
([#3490](#3490))
- Add `SessionId` friendly ID generator and schemas for the new durable
Session primitive. Exported from `@trigger.dev/core/v3/isomorphic`
alongside `RunId`, `BatchId`, etc. Ships the
`CreateSessionStreamWaitpoint` request/response schemas alongside the
main Session CRUD.
([#3417](#3417))
- Truncate large error stacks and messages to prevent OOM crashes. Stack
traces are capped at 50 frames (keeping top 5 + bottom 45 with an
omission notice), individual stack lines at 1024 chars, and error
messages at 1000 chars. Applied in parseError, sanitizeError, and OTel
span recording.
([#3405](#3405))

## Server changes

These changes affect the self-hosted Docker image and Trigger.dev Cloud:

- Add a "Back office" tab to `/admin` and a per-organization detail page
at `/admin/back-office/orgs/:orgId`. The first action available on that
page is editing the org's API rate limit: admins can save a
`tokenBucket` override (refill rate, interval, max tokens) and see a
plain-English preview of the resulting sustained rate and burst
allowance. Writes are audit-logged via the server logger.
([#3434](#3434))
- Optional `DEPLOY_REGISTRY_ECR_DEFAULT_REPOSITORY_POLICY` env var to
apply a default repository policy when the webapp creates new ECR repos
([#3467](#3467))
- Ship the Errors page to all users, with a polish + bug-fix pass:
pinned "No channel" item in the Slack alert channel picker,
viewer-timezone alert timestamps via Slack's `<!date^>` token, Activity
sparkline peak tooltip, centered loading spinner and bug-icon empty
state on the error detail page, ellipsis on the Configure alerts
trigger.
([#3477](#3477))
- Configure the set of machine presets to build boot snapshots for at
deploy time via `COMPUTE_TEMPLATE_MACHINE_PRESETS` (CSV of preset names,
default `small-1x`). Use `COMPUTE_TEMPLATE_MACHINE_PRESETS_REQUIRED`
(CSV, default = full PRESETS list) to scope which preset failures fail a
required-mode deploy. Optional preset failures are logged and don't
block the deploy.
([#3492](#3492))
- Regenerating a RuntimeEnvironment API key no longer invalidates the
previous key immediately. The old key is recorded in a new
`RevokedApiKey` table with a 24 hour grace window, and
`findEnvironmentByApiKey` falls back to it when the submitted key
doesn't match any live environment. The grace window can be ended early
(or extended) by updating `expiresAt` on the row.
([#3420](#3420))
- Add the `Session` primitive — a durable, task-bound, bidirectional I/O
channel that outlives a single run and acts as the run manager for
`chat.agent`. Ships the Postgres `Session` + `SessionRun` tables,
ClickHouse `sessions_v1` + replication service, the `sessions` JWT
scope, and the public CRUD + realtime routes (`/api/v1/sessions`,
`/realtime/v1/sessions/:session/:io`) including `end-and-continue` for
server-orchestrated run handoffs and session-stream waitpoints.
([#3417](#3417))
- Add `KUBERNETES_POD_DNS_NDOTS_OVERRIDE_ENABLED` flag (off by default)
that overrides the cluster default and sets `dnsConfig.options.ndots` on
runner pods (defaulting to 2, configurable via
`KUBERNETES_POD_DNS_NDOTS`). Kubernetes defaults pods to `ndots: 5`, so
any name with fewer than 5 dots — including typical external domains
like `api.example.com` — is first walked through every entry in the
cluster search list (`<ns>.svc.cluster.local`, `svc.cluster.local`,
`cluster.local`) before being tried as-is, turning one resolution into
4+ CoreDNS queries (×2 with A+AAAA). Using a lower `ndots` value reduces
DNS query amplification in the `cluster.local` zone.
  
Note: before enabling, make sure no code path relies on search-list
expansion for names with dots ≥ the configured value — those names will
hit their as-is form first and could resolve externally before falling
back to the cluster search path.
([#3441](#3441))
- Vercel integration option to disable auto promotions
([#3376](#3376))
- Make it clear in the admin that feature flags are global and should
rarely be changed.
([#3408](#3408))
- Admin worker groups API: add GET loader and expose more fields on
POST. ([#3390](#3390))
- Add 60s fresh / 60s stale SWR cache to `getEntitlement` in
`platform.v3.server.ts`. Eliminates a synchronous billing-service HTTP
round trip on every trigger. Reuses the existing `platformCache` (LRU
memory + Redis) pattern already used for `limits` and `usage`. Cache key
is `${orgId}`. Errors return a permissive `{ hasAccess: true }` fallback
(existing behavior) and are also cached to prevent thundering-herd on
billing outages.
([#3388](#3388))
- Show a `MicroVM` badge next to the region name on the regions page.
([#3407](#3407))
- Increase default maximum project count per organization from 10 to 25
([#3409](#3409))
- Merge execution snapshot creation into the dequeue taskRun.update
transaction, reducing 2 DB commits to 1 per dequeue operation
([#3395](#3395))
- Add per-worker Node.js heap metrics to the OTel meter —
`nodejs.memory.heap.used`, `nodejs.memory.heap.total`,
`nodejs.memory.heap.limit`, `nodejs.memory.external`,
`nodejs.memory.array_buffers`, `nodejs.memory.rss`. Host-metrics only
publishes RSS, which overstates V8 heap by the external + native
footprint; these give direct heap visibility per cluster worker so
`NODE_MAX_OLD_SPACE_SIZE` can be sized against observed heap peaks
rather than RSS.
([#3437](#3437))
- Tag Prisma spans with `db.datasource: "writer" | "replica"` so
monitors and trace queries can distinguish the writer pool from the
replica pool. Applies to all `prisma:engine:*` spans (including
`prisma:engine:connection` used by the connection-pool monitors) and the
outer `prisma:client:operation` span.
([#3422](#3422))
- Clarify the cross-region intent in the Terraform and AI-prompt helpers
on the Add Private Connection page. Both already default
`supported_regions` to `["us-east-1", "eu-central-1"]`; added an inline
comment / parenthetical so the user understands why both regions are
listed (Trigger.dev runs in both, so the service must be consumable from
either).
([#3465](#3465))
- Add `RUN_ENGINE_READ_REPLICA_SNAPSHOTS_SINCE_ENABLED` flag (default
off) to route the Prisma reads inside `RunEngine.getSnapshotsSince`
through the read-only replica client. Offloads the snapshot polling
queries (fired by every running task runner) from the primary. When
disabled, behavior is unchanged.
([#3423](#3423))
- Stop creating TaskRunTag records and _TaskRunToTaskRunTag join table
entries during task triggering. The denormalized runTags string array on
TaskRun already stores tag names, making the M2M relation redundant
write overhead.
([#3369](#3369))
- Stop writing per-tick state (`lastScheduledTimestamp`,
`nextScheduledTimestamp`, `lastRunTriggeredAt`) on `TaskSchedule` and
`TaskScheduleInstance`. The schedule engine now carries the previous
fire time forward via the worker queue payload, eliminating ~270K
dead-tuple-driven autovacuums per year on these hot tables and the
associated `IO:XactSync` mini-spikes on the writer. Customer-facing
`payload.lastTimestamp` semantics are unchanged.
([#3476](#3476))
- Replace the expensive DISTINCT query for task filter dropdowns with a
dedicated TaskIdentifier registry table backed by Redis. Environments
migrate automatically on their next deploy, with a transparent fallback
to the legacy query for unmigrated environments. Also fixes duplicate
dropdown entries when a task changes trigger source, and adds
active/archived grouping for removed tasks. Moves BackgroundWorkerTask
reads in the trigger hot path to the read replica.
([#3368](#3368))
- Public Access Tokens (PATs) minted before an API key rotation now keep
working during the 24h grace window. `validatePublicJwtKey` falls back
to any non-expired `RevokedApiKey` rows for the signing environment when
the primary signature check against the env's current `apiKey` fails.
The fallback query only runs on the failure path, so the hot success
path is unchanged.
([#3464](#3464))
- Batch items that hit the environment queue size limit now fast-fail
without
retries and without creating pre-failed TaskRuns.
([#3352](#3352))
- Show the cancel button in the runs list for runs in `DEQUEUED` status.
`DEQUEUED` was missing from `NON_FINAL_RUN_STATUSES` so the list hid the
button even though the single run page allowed it.
([#3421](#3421))
- Reduce 5xx feedback loops on hot debounce keys by quantizing
`delayUntil`,
  adding an unlocked fast-path skip, and gracefully handling redlock
contention in `handleDebounce` so the SDK no longer retries into a herd.
([#3453](#3453))
- Fix RSS memory leak in the realtime proxy routes. `/realtime/v1/runs`,
`/realtime/v1/runs/:id`, and `/realtime/v1/batches/:id` called `fetch()`
into Electric with no abort signal, so when a client disconnected mid
long-poll, undici kept the upstream socket open and buffered response
chunks that would never be consumed — retained only in RSS, invisible to
V8 heap tooling. Thread `getRequestAbortSignal()` through
`RealtimeClient.streamRun/streamRuns/streamBatch` to `longPollingFetch`
and cancel the upstream body in the error path. Isolated reproducer
showed ~44 KB retained per leaked request; signal propagation releases
it cleanly.
([#3442](#3442))
- Fix memory leak where every aborted SSE connection pinned the full
request/response graph on Node 20, caused by `AbortSignal.any()` in
`sse.ts` retaining its source signals indefinitely (see
nodejs/node#54614, nodejs/node#55351). Also clear the
`setTimeout(abort)` timer in `entry.server.tsx` so successful HTML
renders don't pin the React tree for 30s per request.
([#3430](#3430))
- Preserve filters on the queues page when submitting modal actions.
([#3471](#3471))
- Fix Redis connection leak in realtime streams and broken abort signal
propagation.
  
**Redis connections**: Non-blocking methods (ingestData, appendPart,
getLastChunkIndex) now share a single Redis connection instead of
creating one per request. streamResponse still uses dedicated
connections (required for XREAD BLOCK) but now tears them down
immediately via disconnect() instead of graceful quit(), with a 15s
inactivity fallback.
  
**Abort signal**: request.signal is broken in Remix/Express due to a
Node.js undici GC bug (nodejs/node#55428) that severs the signal chain
when Remix clones the Request internally. Added getRequestAbortSignal()
wired to Express res.on("close") via httpAsyncStorage, which fires
reliably on client disconnect. All SSE/streaming routes updated to use
it. ([#3399](#3399))
- Prevent dashboard crash (React error #31) when span accessory item
text is not a string. Filters out malformed accessory items in
SpanCodePathAccessory instead of passing objects to React as children.
([#3400](#3400))
- Upgrade Remix packages from 2.1.0 to 2.17.4 to address security
vulnerabilities in React Router
([#3372](#3372))
- Fix Vercel integration settings page (remove redundant section
toggles) and improve the Vercel onboarding flow so the modal closes
after connecting a GitHub repo and the marketplace `next` URL is
preserved across the GitHub app install redirect.
([#3424](#3424))

<details>
<summary>Raw changeset output</summary>

# Releases
## @trigger.dev/[email protected]

### Patch Changes

-   Updated dependencies:
    -   `@trigger.dev/[email protected]`

## [email protected]

### Patch Changes

- Add `--no-browser` flag to `init` and `login` to skip auto-opening the
browser during authentication. Also error loudly when `init` is run
without `--yes` under non-TTY stdin (previously default-and-exited
silently, leaving the project half-initialized). Both commands now show
an `Examples` section in `--help`.
([#3483](#3483))
-   Updated dependencies:
    -   `@trigger.dev/[email protected]`
    -   `@trigger.dev/[email protected]`
    -   `@trigger.dev/[email protected]`

## @trigger.dev/[email protected]

### Patch Changes

- Add `isReplay` boolean to the run context (`ctx.run.isReplay`),
derived from the existing `replayedFromTaskRunFriendlyId` database
field. Defaults to `false` for backwards compatibility.
([#3454](#3454))
- Redact the `resolveWaitpoint` runtime log so it only emits `id` and
`type` instead of the full completed waitpoint. Previously the log
printed the entire waitpoint (including `output`) to stdout in
production runs, which could leak sensitive payloads. The value returned
by `wait.forToken()` is unchanged.
([#3490](#3490))
- Add `SessionId` friendly ID generator and schemas for the new durable
Session primitive. Exported from `@trigger.dev/core/v3/isomorphic`
alongside `RunId`, `BatchId`, etc. Ships the
`CreateSessionStreamWaitpoint` request/response schemas alongside the
main Session CRUD.
([#3417](#3417))
- Truncate large error stacks and messages to prevent OOM crashes. Stack
traces are capped at 50 frames (keeping top 5 + bottom 45 with an
omission notice), individual stack lines at 1024 chars, and error
messages at 1000 chars. Applied in parseError, sanitizeError, and OTel
span recording.
([#3405](#3405))

## @trigger.dev/[email protected]

### Patch Changes

-   Updated dependencies:
    -   `@trigger.dev/[email protected]`
    -   `@trigger.dev/[email protected]`
    -   `@trigger.dev/[email protected]`

## @trigger.dev/[email protected]

### Patch Changes

-   Updated dependencies:
    -   `@trigger.dev/[email protected]`

## @trigger.dev/[email protected]

### Patch Changes

-   Updated dependencies:
    -   `@trigger.dev/[email protected]`

## @trigger.dev/[email protected]

### Patch Changes

-   Updated dependencies:
    -   `@trigger.dev/[email protected]`

## @trigger.dev/[email protected]

### Patch Changes

-   Updated dependencies:
    -   `@trigger.dev/[email protected]`

## @trigger.dev/[email protected]

### Patch Changes

-   Updated dependencies:
    -   `@trigger.dev/[email protected]`

</details>

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants