Skip to content

Version Packages - #1

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@executor-js/cli@0.2.61

Patch Changes

@executor-js/config@1.6.11

Patch Changes

@executor-js/execution@1.6.11

Patch Changes

  • Updated dependencies [2e5aa16, 4a08d8d]:
    • @executor-js/sdk@1.6.11
    • @executor-js/codemode-core@1.6.11

@executor-js/sdk@1.6.11

Patch Changes

  • #2056 2e5aa16 Thanks @RhysSullivan! - Request every scope a resource advertises during OAuth scope discovery, bounded by an 8 KiB scope-string budget instead of a 100-scope count. Resources with many fine-grained scopes previously received a token missing the ones it needed. Health checks without a probe no longer replace a tool-sync failure verdict with "healthy".

  • #2061 4a08d8d Thanks @RhysSullivan! - Toolkit sessions no longer walk the whole workspace catalog on connect, search, or describe: the toolkit's access patterns narrow the tool rows core reads. Tools reads no longer wait on re-listing catalogs that are only older than the freshness TTL; those rebuild in the background while the read answers from the persisted rows. Stale-marked and config-revised catalogs still gate the read within the grace budget.

@executor-js/vite-plugin@0.0.71

Patch Changes

@executor-js/runtime-quickjs@1.6.11

Patch Changes

  • Updated dependencies []:
    • @executor-js/codemode-core@1.6.11

@executor-js/plugin-desktop-settings@1.6.11

Patch Changes

@executor-js/plugin-example@1.6.11

Patch Changes

@executor-js/plugin-file-secrets@1.6.11

Patch Changes

@executor-js/plugin-graphql@1.6.11

Patch Changes

  • Updated dependencies [29413d8, 31b24b8, 2e5aa16, 4a08d8d]:
    • @executor-js/react@1.4.74
    • @executor-js/sdk@1.6.11
    • @executor-js/api@1.4.74
    • @executor-js/config@1.6.11

@executor-js/plugin-keychain@1.6.11

Patch Changes

@executor-js/plugin-mcp@1.6.11

Patch Changes

  • Updated dependencies [29413d8, 31b24b8, 2e5aa16, 4a08d8d]:
    • @executor-js/react@1.4.74
    • @executor-js/sdk@1.6.11
    • @executor-js/api@1.4.74
    • @executor-js/config@1.6.11

@executor-js/plugin-onepassword@1.6.11

Patch Changes

@executor-js/plugin-openapi@1.6.11

Patch Changes

  • Updated dependencies [29413d8, 31b24b8, 2e5aa16, 4a08d8d]:
    • @executor-js/react@1.4.74
    • @executor-js/sdk@1.6.11
    • @executor-js/api@1.4.74
    • @executor-js/config@1.6.11

@executor-js/plugin-toolkits@1.5.46

Patch Changes

  • #2061 4a08d8d Thanks @RhysSullivan! - Toolkit sessions no longer walk the whole workspace catalog on connect, search, or describe: the toolkit's access patterns narrow the tool rows core reads. Tools reads no longer wait on re-listing catalogs that are only older than the freshness TTL; those rebuild in the background while the read answers from the persisted rows. Stale-marked and config-revised catalogs still gate the read within the grace budget.

  • Updated dependencies [29413d8, 31b24b8, 2e5aa16, 4a08d8d]:

    • @executor-js/react@1.4.74
    • @executor-js/sdk@1.6.11
    • @executor-js/api@1.4.74

@executor-js/codemode-core@1.6.11

executor@1.6.11

Patch Changes

  • #2066 c6d1083 Thanks @RhysSullivan! - Prefer browser sign-in when a matching OAuth client is available, while preserving a user’s chosen method when clients finish loading.

  • #2050 24adb12 Thanks @RhysSullivan! - Accept Slack bot and user OAuth token envelopes during sign-in and token refresh.

  • Updated dependencies [2e5aa16, 4a08d8d]:

    • @executor-js/sdk@1.6.11
    • @executor-js/local@1.6.11
    • @executor-js/api@1.4.74
    • @executor-js/runtime-quickjs@1.6.11

@executor-js/cloud@1.4.72

Patch Changes

  • #2099 9e143d9 Thanks @RhysSullivan! - An admin who resumes a paused execution from a different MCP session (for example after the client reconnects) keeps workspace-write access. The forwarded resume now carries the requester's access to the session that owns the execution, so a pending addServer, addSpec, or similar write no longer fails with org_write_denied.

  • #2119 4a52307 Thanks @RhysSullivan! - Require authenticator verification for organization settings while preserving shared workspace reads and API-key access.

  • Updated dependencies [29413d8, 31b24b8, 2e5aa16, 4a08d8d]:

    • @executor-js/react@1.4.74
    • @executor-js/sdk@1.6.11
    • @executor-js/plugin-toolkits@1.5.46
    • @executor-js/mcp-apps-shell@1.4.22
    • @executor-js/plugin-graphql@1.6.11
    • @executor-js/plugin-mcp@1.6.11
    • @executor-js/plugin-openapi@1.6.11
    • @executor-js/plugin-workos-vault@0.0.2
    • @executor-js/api@1.4.74
    • @executor-js/execution@1.6.11
    • @executor-js/vite-plugin@0.0.71
    • @executor-js/cloudflare@0.0.53
    • @executor-js/host-mcp@1.4.4
    • @executor-js/runtime-dynamic-worker@1.4.4
    • @executor-js/runtime-quickjs@1.6.11

@executor-js/host-selfhost@0.0.53

Patch Changes

  • Updated dependencies [29413d8, 31b24b8, 2e5aa16, 4a08d8d]:
    • @executor-js/react@1.4.74
    • @executor-js/sdk@1.6.11
    • @executor-js/plugin-toolkits@1.5.46
    • @executor-js/app@1.4.4
    • @executor-js/mcp-apps-shell@1.4.22
    • @executor-js/plugin-graphql@1.6.11
    • @executor-js/plugin-mcp@1.6.11
    • @executor-js/plugin-openapi@1.6.11
    • @executor-js/analytics@0.1.18
    • @executor-js/api@1.4.74
    • @executor-js/execution@1.6.11
    • @executor-js/host-mcp@1.4.4
    • @executor-js/plugin-encrypted-secrets@0.0.53
    • @executor-js/plugin-provider-service-split@0.0.25
    • @executor-js/runtime-quickjs@1.6.11

@executor-js/local@1.6.11

Patch Changes

  • Updated dependencies [29413d8, 31b24b8, 2e5aa16, 4a08d8d]:
    • @executor-js/react@1.4.74
    • @executor-js/sdk@1.6.11
    • @executor-js/plugin-toolkits@1.5.46
    • @executor-js/app@1.4.4
    • @executor-js/mcp-apps-shell@1.4.22
    • @executor-js/plugin-graphql@1.6.11
    • @executor-js/plugin-mcp@1.6.11
    • @executor-js/plugin-onepassword@1.6.11
    • @executor-js/plugin-openapi@1.6.11
    • @executor-js/analytics@0.1.18
    • @executor-js/api@1.4.74
    • @executor-js/config@1.6.11
    • @executor-js/execution@1.6.11
    • @executor-js/vite-plugin@0.0.71
    • @executor-js/host-mcp@1.4.4
    • @executor-js/plugin-desktop-settings@1.6.11
    • @executor-js/plugin-example@1.6.11
    • @executor-js/plugin-file-secrets@1.6.11
    • @executor-js/plugin-keychain@1.6.11
    • @executor-js/plugin-provider-service-split@0.0.25
    • @executor-js/runtime-quickjs@1.6.11

@executor-js/e2e@0.0.51

Patch Changes

  • Updated dependencies [2e5aa16, 4a08d8d]:
    • @executor-js/sdk@1.6.11
    • @executor-js/plugin-toolkits@1.5.46
    • @executor-js/plugin-graphql@1.6.11
    • @executor-js/plugin-mcp@1.6.11
    • @executor-js/plugin-openapi@1.6.11
    • @executor-js/api@1.4.74

@executor-js/example-all-plugins@0.0.72

Patch Changes

  • Updated dependencies [2e5aa16, 4a08d8d]:
    • @executor-js/sdk@1.6.11
    • @executor-js/plugin-graphql@1.6.11
    • @executor-js/plugin-mcp@1.6.11
    • @executor-js/plugin-onepassword@1.6.11
    • @executor-js/plugin-openapi@1.6.11
    • @executor-js/plugin-workos-vault@0.0.2
    • @executor-js/plugin-file-secrets@1.6.11
    • @executor-js/plugin-keychain@1.6.11

@executor-js/example-docs-sdk-quickstart@0.0.57

Patch Changes

  • Updated dependencies [2e5aa16, 4a08d8d]:
    • @executor-js/sdk@1.6.11
    • @executor-js/plugin-openapi@1.6.11

@executor-js/analytics@0.1.18

Patch Changes

  • Updated dependencies []:
    • @executor-js/execution@1.6.11

@executor-js/api@1.4.74

Patch Changes

  • Updated dependencies [2e5aa16, 4a08d8d]:
    • @executor-js/sdk@1.6.11
    • @executor-js/execution@1.6.11
    • @executor-js/host-mcp@1.4.4

@executor-js/cloudflare@0.0.53

Patch Changes

  • Updated dependencies [2e5aa16, 4a08d8d]:
    • @executor-js/sdk@1.6.11
    • @executor-js/api@1.4.74
    • @executor-js/execution@1.6.11
    • @executor-js/host-mcp@1.4.4

@executor-js/mcp-apps-shell@1.4.22

Patch Changes

  • Updated dependencies [29413d8, 31b24b8]:
    • @executor-js/react@1.4.74
    • @executor-js/runtime-quickjs@1.6.11

@executor-js/runtime-workerd-subprocess@0.0.26

Patch Changes

  • Updated dependencies []:
    • @executor-js/codemode-core@1.6.11

@executor-js/onboarding-demo@0.0.6

Patch Changes

  • Updated dependencies [29413d8, 31b24b8, 2e5aa16, 4a08d8d]:
    • @executor-js/react@1.4.74
    • @executor-js/sdk@1.6.11
    • @executor-js/plugin-mcp@1.6.11
    • @executor-js/plugin-openapi@1.6.11

@executor-js/plugin-encrypted-secrets@0.0.53

Patch Changes

@executor-js/plugin-provider-service-split@0.0.25

Patch Changes

  • Updated dependencies [2e5aa16, 4a08d8d]:
    • @executor-js/sdk@1.6.11
    • @executor-js/plugin-openapi@1.6.11

@executor-js/react@1.4.74

Patch Changes

  • #2062 29413d8 Thanks @RhysSullivan! - Tool policies set from an account section of the integration Tools tab now apply to that connection only, and each account header gets a menu to set a policy for the whole connection. Members no longer see policy controls they cannot use, and a refused policy write shows the server's reason.

  • #2051 31b24b8 Thanks @RhysSullivan! - Show restricted integration actions as disabled controls with an admin explanation. Members can browse the catalog and add personal connections to existing integrations.

  • Updated dependencies [2e5aa16, 4a08d8d]:

    • @executor-js/sdk@1.6.11
    • @executor-js/api@1.4.74

@executor-js/desktop@1.6.11


Summary by cubic

Bumps all packages to their next patch versions and rolls every pending changeset into the changelogs; this is the Changesets release PR, so merging publishes the new versions to npm.

Release highlights

  • OAuth scope discovery requests every advertised scope within an 8 KiB budget instead of a 100-scope cap.
  • Toolkit reads no longer walk the whole workspace catalog or wait on freshness-TTL refreshes.
  • Slack bot and user OAuth token envelopes are accepted during sign-in and refresh.
  • Sign-in prefers browser when a matching OAuth client is present.
  • Tool policies are set per connection, and members no longer see policy controls they can't use.
  • Resuming a paused execution from another MCP session keeps workspace-write access.
  • Organization settings now require authenticator verification.

Written for commit 2b87591. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: fbfa976e-cad3-4088-8ba5-eeb931a35a6c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants