Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
242 commits
Select commit Hold shift + click to select a range
b645a1c
Fix MongoDB VariableSerializer dropping StorageDriverType (#8047)
sfmskywalker Sep 11, 2026
6b9f744
Fix MongoDB JsonObject/JsonArray/JsonValue serialization (#8048)
sfmskywalker Sep 11, 2026
a54d3b7
Implement TryMarkInterruptedAsync on Mongo + Dapper WorkflowInstanceS…
sfmskywalker Sep 12, 2026
01bf9ad
fix(dapper): honor BeforeLastUpdated in the workflow instance store (…
sfmskywalker Sep 12, 2026
e6d5989
fix: AddOpenIdConnectAuth no longer throws on provider registration (…
sfmskywalker Sep 12, 2026
c085ee5
fix: accept static feature catalog names for dashboard modules
cursoragent Sep 12, 2026
c9a36b3
fix: restrict static feature catalog matching to Elsa-prefixed names
cursoragent Sep 12, 2026
8d5ece8
test: reject Acme.Identity last-segment collisions
cursoragent Sep 12, 2026
e8f0744
Merge pull request #1026 from elsa-workflows/cursor/fix-static-featur…
sfmskywalker Sep 12, 2026
b267a8b
fix: open Execution Details drawer when clicking an Executions row (#…
sfmskywalker Sep 12, 2026
d7255c4
fix: allow TryMarkInterrupted to promote Finished/Cancelled (#190)
sfmskywalker Sep 12, 2026
7a30510
fix(ci): pack wasm-react against the local wasm tarball (#1030)
sfmskywalker Sep 12, 2026
c9f83e5
fix: gate Cancelled interrupt promote behind allowFinishedCancelled (…
sfmskywalker Sep 12, 2026
99de962
chore: bump Elsa.Api.Client to 3.8.1 (#1035)
sfmskywalker Sep 12, 2026
0619be9
chore: bump ElsaVersion and ElsaStudioVersion to 3.8.1 (#192)
sfmskywalker Sep 12, 2026
249d0f0
fix(keyvalues): tenant-isolate MemoryKeyValueStore (#8141)
sfmskywalker Sep 14, 2026
1c72dc0
chore: bump Elsa.Api.Client to 3.8.2 (#1043)
sfmskywalker Sep 15, 2026
e7d05ef
chore: bump ElsaVersion and ElsaStudioVersion to 3.8.2 (#207)
sfmskywalker Sep 15, 2026
9bff3f7
chore(deps): bump Elsa.Api.Client to 3.8.4 (#1052) (#1054)
sfmskywalker Sep 20, 2026
154ba15
chore: bump ElsaVersion and ElsaStudioVersion to 3.8.4 (#215)
sfmskywalker Sep 20, 2026
4079185
chore: set packages base_version to 3.9.0 (#217)
sfmskywalker Sep 22, 2026
f68d5b0
chore: packages base_version 3.9.0 + Elsa.Api.Client 3.8.4 (#1056)
sfmskywalker Sep 22, 2026
9d0e6fa
chore: pin ElsaVersion/ElsaStudioVersion to 3.8.4 (interim) (#218)
sfmskywalker Sep 22, 2026
fc72be2
ci: run pr workflow for release/* branches (#1057)
sfmskywalker Sep 24, 2026
2b210a5
ci: run pr workflow for release/* branches (#219)
sfmskywalker Sep 24, 2026
338c90a
chore: pin ElsaVersion to 3.9.0-preview.5708
cursoragent Sep 24, 2026
583f758
fix: backport TryUpdateLatestAsync from main (#216)
cursoragent Sep 24, 2026
ecc6729
Merge pull request #221 from elsa-workflows/cursor/pin-elsa-3-9-0-pre…
sfmskywalker Sep 24, 2026
2e9370b
chore: forward-merge release/3.8.4 into release/3.9.0
cursoragent Sep 25, 2026
0320691
chore: forward-merge release/3.8.4 into release/3.9.0
cursoragent Sep 25, 2026
90a22b4
test: register ITimeFormatter in ActivityExecutionDetailsTests
cursoragent Sep 25, 2026
51b176b
Merge pull request #1059 from elsa-workflows/forward-merge/3.8.4-into…
sfmskywalker Sep 25, 2026
9105c27
chore: forward-merge release/3.9.0 into main
cursoragent Sep 25, 2026
194fac3
Merge pull request #224 from elsa-workflows/forward-merge/3.8.4-into-…
sfmskywalker Sep 25, 2026
05bc3c8
fix(environments): defer environments load off Blazor Server host sta…
cursoragent Sep 25, 2026
44e502f
fix(environments): retry failed loads and select default env before c…
cursoragent Sep 25, 2026
869f45f
fix(environments): cache EnvironmentLoader only after a successful load
cursoragent Sep 25, 2026
c8ed24f
fix(environments): log circuit teardown at Debug in EnvironmentLoader
cursoragent Sep 25, 2026
8869132
fix(persistence): refuse Finished rows in TryMarkInterruptedAsync
cursoragent Sep 25, 2026
f4add6e
fix(environments): load environments once via IFeatureService wrapper
cursoragent Sep 25, 2026
720ca63
Merge pull request #226 from elsa-workflows/fix/225-trymarkinterrupte…
sfmskywalker Sep 25, 2026
3e24167
Merge pull request #1064 from elsa-workflows/fix/1062-environments-bl…
sfmskywalker Sep 25, 2026
43ddefd
chore: forward-merge release/3.9.0 into main
cursoragent Sep 25, 2026
daf4ba7
chore: merge origin/main into forward-merge/3.9.0-into-main
cursoragent Sep 25, 2026
1805cac
fix(mongodb): tenant-scope TryMarkInterruptedAsync and ordered Summar…
cursoragent Sep 25, 2026
cbd6490
fix(dapper): default implementation for ISqlDialect.Update(table, fie…
cursoragent Sep 25, 2026
9102962
fix(hosts): branding reads "Elsa Studio 3.9"
cursoragent Sep 26, 2026
46769a2
Merge pull request #236 from elsa-workflows/fix/235-sqldialect-update…
sfmskywalker Sep 26, 2026
3a7ae6b
Merge pull request #230 from elsa-workflows/fix/228-mongo-instance-st…
sfmskywalker Sep 26, 2026
1a2b1fd
fix(mongodb): tenant-scope paged definition summaries and TenantAgnos…
cursoragent Sep 26, 2026
7a61000
fix(mongodb): tenant-owned upsert filter so cross-tenant saves cannot…
cursoragent Sep 26, 2026
82e240b
test(mongodb): disambiguate SaveManyAsync overloads in tenant-owned u…
cursoragent Sep 26, 2026
48a0f63
test(mongodb): pin forged-owner upsert refusal and assert DuplicateKe…
cursoragent Sep 26, 2026
cfcc0b6
Merge pull request #246 from elsa-workflows/fix/239-mongo-definition-…
sfmskywalker Sep 28, 2026
64f9711
Merge pull request #248 from elsa-workflows/fix/242-mongo-upsert-tena…
sfmskywalker Sep 28, 2026
6ee02b1
fix(hosts): derive branding from ToolVersion 3.9
cursoragent Sep 28, 2026
10db394
fix(dapper): skip duplicate AggregateFaultCount in V3_7 runtime migra…
cursoragent Sep 28, 2026
aa6b1a3
Merge pull request #1071 from elsa-workflows/fix/1063-host-branding-3.9
sfmskywalker Sep 28, 2026
c71105b
Merge pull request #251 from elsa-workflows/cursor/fix-dapper-v3-7-du…
sfmskywalker Sep 28, 2026
2b1127f
fix(secrets): bulk delete filters by SecretId (#253)
cursoragent Sep 28, 2026
aa77da6
fix(dapper): match both Postgres and PostgreSQL provider names in mig…
cursoragent Sep 28, 2026
87425a2
test(dapper): fix IMigrationProcessor namespace in processor-name test
cursoragent Sep 28, 2026
e1bc44a
fix(dapper): match every FluentMigrator 7.2 PostgreSQL* processor name
cursoragent Sep 28, 2026
2cb5b75
Merge pull request #256 from elsa-workflows/cursor/fix-secrets-bulk-d…
sfmskywalker Sep 28, 2026
86b6974
chore(deps): bump ElsaVersion to 3.9.0-preview.5724
cursoragent Sep 28, 2026
f3631ec
fix(dapper): restore alias-aware IfDatabase list and narrow PG persis…
cursoragent Sep 28, 2026
cfbbaad
chore(deps): bump ElsaStudioVersion to 3.9.0-preview.1757
cursoragent Sep 28, 2026
9eadc46
fix(dapper): quote PostgreSQL dialect identifiers and include upsert PK
cursoragent Sep 28, 2026
23fcce2
fix(dapper): use Concat for PostgreSQL identifier quoting
cursoragent Sep 28, 2026
9b14229
fix(dapper): map Npgsql DateTime to DateTimeOffset on PostgreSQL
cursoragent Sep 28, 2026
39ae028
fix(dapper): terminate PostgreSQL upsert so SaveMany can batch
cursoragent Sep 28, 2026
dc5b341
Merge pull request #261 from elsa-workflows/cursor/bump-elsaversion-p…
sfmskywalker Sep 28, 2026
14a289d
fix(dapper): quote shared query-builder identifiers via dialect hook
cursoragent Sep 28, 2026
389c1a7
fix(dapper): emit PG boolean literals through a dialect hook
cursoragent Sep 28, 2026
eec9581
fix(dapper): quote LessThan identifiers on the 3.9 query builder
cursoragent Sep 28, 2026
8526e90
test(dapper): register WriteLine so PG publish rematerializes
cursoragent Sep 28, 2026
3a58d18
fix(dapper): quote instance-search Id to match the PG schema
cursoragent Sep 28, 2026
dc596ed
fix(dapper): use Id in instance search and unblock the PG E2E
cursoragent Sep 28, 2026
a7a0bf6
docs(dapper): note that ID→Id fixes case-sensitive SQL Server
cursoragent Sep 28, 2026
9d9049e
Merge pull request #258 from elsa-workflows/cursor/fix-dapper-postgre…
sfmskywalker Sep 28, 2026
d70549a
fix(dapper): create KeyValues, add SerializedOptions, and fix prefix …
cursoragent Sep 28, 2026
e1b92e1
fix(persistence): atomic TryDeleteAsync on Dapper and Mongo (#260)
cursoragent Sep 28, 2026
6ef1f5f
ci: retrigger pr workflow for #260
cursoragent Sep 28, 2026
95c7047
ci: touch TryDelete tests so pr.yml paths match
cursoragent Sep 28, 2026
81f9fb6
fix(dapper): keep QuoteIdent with StartsWith binding after #259 rebase
cursoragent Sep 28, 2026
3f110a2
test(dapper): fail if StartsWith drops QuoteIdent on PostgreSQL
cursoragent Sep 28, 2026
fa7ad8f
3.9 identity & access polish: API client collision, permission-gated …
sfmskywalker Sep 29, 2026
505ec6e
Hide in-page actions the user cannot perform (#1076)
sfmskywalker Sep 29, 2026
8b0749f
Drop the tenant scope label from the Users pages (#1077)
sfmskywalker Sep 29, 2026
b7e13f1
test(workflows): cover the remaining permission-gated actions (#1080)
sfmskywalker Sep 29, 2026
08c0fe7
feat(oidc): add sign-out to the app bar (#1081)
sfmskywalker Sep 29, 2026
667e1fc
test(shell): guard the Server host's persist-component-state tag (#1088)
sfmskywalker Sep 29, 2026
3f2d532
test(security): wait for navigation after async click handlers (#1089)
sfmskywalker Sep 30, 2026
8f67b3f
fix(auth-ui): submit the sign-in form with Enter (#1090)
sfmskywalker Sep 30, 2026
677fe32
fix(shell): show a loading state on the dashboard and open the user m…
sfmskywalker Sep 30, 2026
8a5b1df
feat(studio): one access-denied presentation for pages the user can't…
sfmskywalker Sep 30, 2026
8b240aa
feat(shell): send users who can't view the landing page to their firs…
sfmskywalker Sep 30, 2026
0e443b0
test(workflows): wait for menu popovers in permission tests
sfmskywalker Sep 30, 2026
74e3839
refactor(tests): share one TestLocalizer across test projects
sfmskywalker Sep 30, 2026
8fdf85f
test(workflows): scope OpenMenu to the clicked menu's popover
sfmskywalker Sep 30, 2026
44faa1a
Merge pull request #1096 from elsa-workflows/fix/flaky-workflow-permi…
sfmskywalker Sep 30, 2026
a32ee3a
Merge pull request #1098 from elsa-workflows/refactor/shared-test-loc…
sfmskywalker Sep 30, 2026
38c5b59
fix(app-bar): open the language and environment pickers below their b…
sfmskywalker Sep 30, 2026
e7fb3f7
feat(studio): explain refused API calls instead of showing the raw Ap…
sfmskywalker Sep 30, 2026
829f3bb
feat(elsa-identity): revoke the session server-side on sign-out (#1100)
sfmskywalker Sep 30, 2026
e2d7621
test: wait for Studio timer callbacks before disposing test signals (…
sfmskywalker Sep 30, 2026
bd44366
feat(dashboard): open the dashboard to every user and gate widgets by…
sfmskywalker Oct 1, 2026
3688709
test: share bounded blocking timer callback across Studio timer tests…
sfmskywalker Oct 1, 2026
aa64667
fix(persistence): KeyValues, SerializedOptions, and atomic TryDeleteA…
sfmskywalker Oct 2, 2026
dc30ffb
Merge pull request #267 from elsa-workflows/cursor/dapper-keyvalues-b…
sfmskywalker Oct 2, 2026
baff197
chore(deps): bump ElsaVersion to 3.9.0-preview.5744 and ElsaStudioVer…
cursoragent Oct 2, 2026
69f1441
docs: add .github/reviewers.md and reference it from AGENTS.md
sfmskywalker Oct 3, 2026
36410a6
docs: add .github/reviewers.md and reference it from AGENTS.md
sfmskywalker Oct 3, 2026
778e925
docs: clarify reviewer request timing, automatic reviews and declines
sfmskywalker Oct 3, 2026
b4ea5b7
docs: clarify reviewer request timing, automatic reviews and declines
sfmskywalker Oct 3, 2026
ea8535b
fix(auth): prevent open redirect on OIDC login returnUrl
cursoragent Oct 3, 2026
7ea154f
fix(auth): preserve original return URLs and PathBase
cursoragent Oct 3, 2026
d6e93b0
docs: align reviewers.md with the merge gate and Greptile policy
sfmskywalker Oct 3, 2026
47d8012
docs: align reviewers.md with the merge gate and Greptile policy
sfmskywalker Oct 3, 2026
cd6f22e
fix(auth): accept only rooted local return paths
cursoragent Oct 3, 2026
8bb6b25
test(auth): construct UrlHelper with ControllerActionDescriptor
cursoragent Oct 3, 2026
f81aa64
Merge pull request #1104 from elsa-workflows/docs/reviewers-list
sfmskywalker Oct 3, 2026
71c0d7d
Merge pull request #272 from elsa-workflows/docs/reviewers-list
sfmskywalker Oct 3, 2026
2842adf
Merge pull request #1105 from elsa-workflows/cursor/fix-oidc-open-red…
sfmskywalker Oct 3, 2026
783d7b1
chore(deps): bump ElsaVersion to 3.9.0-preview.5753 and ElsaStudioVer…
cursoragent Oct 3, 2026
9bba55b
Merge pull request #271 from elsa-workflows/cursor/bump-elsa-preview-…
sfmskywalker Oct 3, 2026
9e19227
chore(deps): bump ElsaVersion to 3.9.0-preview.5757
cursoragent Oct 3, 2026
b597739
Merge pull request #273 from elsa-workflows/cursor/bump-elsaversion-p…
sfmskywalker Oct 3, 2026
1718fad
fix(security): select only visible role permissions
cursoragent Oct 3, 2026
ea1a956
fix(security): trim Roles list and editor copy
cursoragent Oct 3, 2026
c94032a
fix(security): keep covered exact grants on Deselect
cursoragent Oct 3, 2026
0ad1874
Merge pull request #1116 from elsa-workflows/cursor/roles-select-all-…
sfmskywalker Oct 3, 2026
1a8bef5
ci: make nuget.org/npm publish dispatch-only and block 3.10.x
cursoragent Oct 3, 2026
201d7b2
ci: make nuget.org publish dispatch-only and block 3.10.x
cursoragent Oct 3, 2026
7bfefe5
ci: document that publish_nuget is inert on 3.10.x main
cursoragent Oct 3, 2026
19923d2
Merge pull request #1117 from elsa-workflows/cursor/block-310-public-…
sfmskywalker Oct 3, 2026
c638939
Merge pull request #274 from elsa-workflows/cursor/packages-nuget-dis…
sfmskywalker Oct 3, 2026
a27f746
build: pin Elsa 3.10.0-preview.5760 and Studio 3.10.0-preview.1799
cursoragent Oct 3, 2026
74b4424
Merge pull request #275 from elsa-workflows/cursor/elsa-pin-preview-5…
sfmskywalker Oct 3, 2026
199b9a3
build: bump Elsa.Api.Client to 3.9.0 stable
sfmskywalker Oct 4, 2026
a30ed7c
Merge pull request #1119 from elsa-workflows/chore/api-client-3.9.0
sfmskywalker Oct 4, 2026
a418091
ci: fail fast when the NuGet API key is empty
sfmskywalker Oct 4, 2026
22c37a0
ci: fail fast when the NuGet API key is empty
sfmskywalker Oct 4, 2026
7355b1b
Merge pull request #1120 from elsa-workflows/ci/nuget-empty-key-guard
sfmskywalker Oct 4, 2026
6d76404
Merge pull request #276 from elsa-workflows/ci/nuget-empty-key-guard
sfmskywalker Oct 4, 2026
90f5b8b
ci: name FEEDZ_API_KEY in feedz.io empty-key error; pass push keys vi…
sfmskywalker Oct 4, 2026
2addf54
ci: name FEEDZ_API_KEY in feedz.io empty-key error; pass push keys vi…
sfmskywalker Oct 4, 2026
75308d9
chore: pin Elsa 3.9.0 and Elsa Studio 3.9.0 (stable) for the 3.9.0 re…
sfmskywalker Oct 4, 2026
89d4eb9
Merge pull request #278 from elsa-workflows/chore/release-3.9.0-stabl…
sfmskywalker Oct 4, 2026
1b31030
Merge pull request #1121 from elsa-workflows/fix/8600-feedz-wording-e…
sfmskywalker Oct 4, 2026
caaae98
Merge pull request #277 from elsa-workflows/fix/8600-feedz-wording-en…
sfmskywalker Oct 4, 2026
aea4dc5
docs(reviewers): make Elsa 3 Code Review the only merge gate; all bot…
sfmskywalker Oct 4, 2026
d256de5
docs(agents): Greptile is advisory; point to the CR-only merge gate
sfmskywalker Oct 4, 2026
72e79f3
docs(reviewers): make Elsa 3 Code Review the only merge gate; all bot…
sfmskywalker Oct 4, 2026
01a582d
docs(agents): drop Greptile waiver wording; point to the CR-only merg…
sfmskywalker Oct 4, 2026
6fba99f
docs(reviewers): spell out the exact Code Review header and verdict r…
sfmskywalker Oct 4, 2026
2307c3f
docs(reviewers): spell out the exact Code Review header and verdict r…
sfmskywalker Oct 4, 2026
efde64e
Merge pull request #1124 from elsa-workflows/docs/reviewers-cr-only-gate
sfmskywalker Oct 4, 2026
98a185a
Merge pull request #280 from elsa-workflows/docs/reviewers-cr-only-gate
sfmskywalker Oct 4, 2026
91f32da
docs(identity): replace removed SecurityRoot localhost guidance with …
sfmskywalker Oct 4, 2026
257bebc
docs(identity): distinguish 401 and 403 in the bootstrap diagnostic note
sfmskywalker Oct 4, 2026
c902905
docs(identity): drop sign-in claim the store-only diagnostic cannot back
sfmskywalker Oct 4, 2026
1860081
docs(identity): warn about stale bootstrap passwords and how to retir…
sfmskywalker Oct 4, 2026
7876e41
Merge pull request #8612 from elsa-workflows/docs/identity-readme-39-…
sfmskywalker Oct 4, 2026
b98590a
docs(identity): align bootstrap wording in migration guide and startu…
sfmskywalker Oct 4, 2026
093dc19
docs(identity): document shared-store role-ID collision and scope 401…
sfmskywalker Oct 4, 2026
4f7fd42
docs(identity): scope the role-ID collision to a shared AdminRoleName…
sfmskywalker Oct 4, 2026
5d3582b
Merge pull request #8614 from elsa-workflows/docs/identity-bootstrap-…
sfmskywalker Oct 4, 2026
290f797
merge: reconcile Core 3.9.0 release ancestry into main
sfmskywalker Oct 5, 2026
e333ee6
merge: reconcile Core 3.8.1 tenant-isolation backport ancestry
sfmskywalker Oct 5, 2026
dda5e2d
chore: merge current main into Studio forward-merge branch
sfmskywalker Oct 5, 2026
04bc341
docs: record Core release ancestry reconciliation evidence
sfmskywalker Oct 5, 2026
cd39f5f
chore: refresh Studio forward merge with current 3.9 release
sfmskywalker Oct 5, 2026
5cc1904
Merge release/3.9 into main preserving 3.10 publication configuration
sfmskywalker Oct 5, 2026
b76f8fd
Remove duplicate Dapper test friend assembly after reconciliation
sfmskywalker Oct 5, 2026
db59d7d
Reconcile Extensions release fixes into consolidated Core
sfmskywalker Oct 5, 2026
96a0353
Join reconciled Extensions source history after mapped path accounting
sfmskywalker Oct 5, 2026
860e45c
Integrate Extensions release reconciliation and mapped source refresh
sfmskywalker Oct 5, 2026
1faef9f
test(secrets): model backend create capability in permission fixtures
sfmskywalker Oct 5, 2026
3bd9c4d
fix(studio): reconcile remaining release fixes into consolidated sources
sfmskywalker Oct 5, 2026
c445f9f
merge: preserve reconciled Studio source history in Core
sfmskywalker Oct 5, 2026
1245b85
Reference consolidated Elsa module for imported Dapper workflow tests
sfmskywalker Oct 5, 2026
14c6bd6
Construct Dapper concrete store behind atomic-delete interface test
sfmskywalker Oct 5, 2026
dea5695
fix(secrets): honor backend inline-create capability in picker
sfmskywalker Oct 5, 2026
45490a7
fix(studio): preserve backend inline-create capability in secret picker
sfmskywalker Oct 5, 2026
1b06a98
merge: preserve final Studio picker reconciliation history in Core
sfmskywalker Oct 5, 2026
7b07676
Integrate mapped Dapper test project and interface construction fixes
sfmskywalker Oct 5, 2026
70ea301
[skip ci] Merge release reconciliation for 3.8 and 3.9 into main (#285)
sfmskywalker Oct 5, 2026
ab4eb2f
Integrate reconciled Studio source and preserve upstream release history
sfmskywalker Oct 5, 2026
7d7dfb2
Preserve accepted Extensions main history after reviewed PR 285
sfmskywalker Oct 5, 2026
c304c05
Record complete Studio source reconciliation receipt
sfmskywalker Oct 5, 2026
1c1af1c
Record release ancestry and combined catch-up validation
sfmskywalker Oct 5, 2026
2cdfcc5
Fix hosted OIDC logout action for PathBase
sfmskywalker Oct 5, 2026
6da1a33
Cover hosted OIDC logout form under nested PathBase
sfmskywalker Oct 5, 2026
73f8354
Join reconciled Studio OIDC PathBase fix history
sfmskywalker Oct 5, 2026
88c2415
Refresh Studio catchup receipt for hosted logout fix
sfmskywalker Oct 5, 2026
2e87a3e
Record hosted logout regression and updated Studio source pin
sfmskywalker Oct 5, 2026
3b4c49f
Record completed Core hosted logout validation in receipt
sfmskywalker Oct 5, 2026
e712b5e
[skip ci] Merge 3.8 and 3.9 release reconciliation into main (#1061)
sfmskywalker Oct 5, 2026
79b631b
Preserve accepted Studio main history after reviewed PR 1061
sfmskywalker Oct 5, 2026
58fcbe0
Record accepted Studio reconciliation and final source CI
sfmskywalker Oct 5, 2026
1ad1221
Preserve legacy JsonObject fields resembling scalar BSON envelopes
sfmskywalker Oct 5, 2026
4e74548
Preserve nominal JsonObject when legacy BSON resembles scalar envelope
sfmskywalker Oct 5, 2026
27cd771
Disambiguate legacy JsonObject from array as well as scalar envelopes
sfmskywalker Oct 5, 2026
f104501
Preserve legacy JsonObject when fields resemble any incompatible node…
sfmskywalker Oct 5, 2026
6027354
Fix Dapper literal prefix matching
sfmskywalker Oct 5, 2026
3d72c83
Merge commit '58fcbe05f' into codex/persistence-review-mongo
sfmskywalker Oct 5, 2026
734da58
Restrict feature fallback and constrain execution drawer to viewport
sfmskywalker Oct 5, 2026
85ca8b6
Address Studio compatibility review and document Mongo serializer con…
sfmskywalker Oct 5, 2026
80e42dc
Preserve Studio feature namespace and drawer review fix history
sfmskywalker Oct 5, 2026
870807c
Compare Dapper SQLite date filters by instant
sfmskywalker Oct 5, 2026
09a152a
Port reviewed Dapper literal-prefix and timestamp corrections to source
sfmskywalker Oct 5, 2026
4f2835f
Integrate reviewed Mongo legacy object compatibility corrections
sfmskywalker Oct 5, 2026
80c0b3e
Refresh Studio receipt for namespace and viewport corrections
sfmskywalker Oct 5, 2026
a395dcb
Escape Dapper path prefixes across SQL dialects
sfmskywalker Oct 5, 2026
e6cc42c
Port reviewed PostgreSQL backslash-prefix handling to source
sfmskywalker Oct 5, 2026
4927e71
Merge commit 'a395dcbf4fdc565b3f2d057d44595db5a363fcaf' into codex/pe…
sfmskywalker Oct 5, 2026
33d2371
Integrate literal Dapper prefix and SQLite instant comparison correct…
sfmskywalker Oct 5, 2026
daf097c
Apply required braces to literal-prefix regression assertions
sfmskywalker Oct 5, 2026
75f51b9
style: require braces in Dapper prefix tests
sfmskywalker Oct 5, 2026
e378543
style: require braces in Mongo envelope guard
sfmskywalker Oct 5, 2026
0cb7894
style: require braces in Mongo envelope guard
sfmskywalker Oct 5, 2026
591fa0e
test: align SQLite date comparison SQL assertion
sfmskywalker Oct 5, 2026
6ef6df4
test: align SQLite date comparison SQL assertion
sfmskywalker Oct 5, 2026
e6dd8a1
fix: preserve tenant ownership when saving Dapper key values
sfmskywalker Oct 5, 2026
8626e81
fix: preserve tenant ownership when saving Dapper key values
sfmskywalker Oct 5, 2026
3d028a4
[skip ci] Preserve feature namespaces and constrain drawer width (#1125)
sfmskywalker Oct 5, 2026
00c143b
Preserve accepted Studio follow-up main history after PR 1125
sfmskywalker Oct 5, 2026
8514803
Integrate reviewed tenant-safe Dapper saves and full persistence veri…
sfmskywalker Oct 5, 2026
513d598
Refresh complete source receipts and persistence review evidence
sfmskywalker Oct 5, 2026
25551c2
Preserve reviewed Extensions persistence source history after mapped …
sfmskywalker Oct 5, 2026
f237b64
[skip ci] Preserve persistence ownership and legacy query semantics (…
sfmskywalker Oct 5, 2026
5432a22
Preserve accepted Extensions persistence follow-up main history
sfmskywalker Oct 5, 2026
8d4df05
Record accepted Extensions source and final hosted persistence evidence
sfmskywalker Oct 5, 2026
a24de29
fix: bound Dapper key value save retries under concurrent churn
sfmskywalker Oct 5, 2026
6e7f739
fix: bound Dapper key value save retries under concurrent churn
sfmskywalker Oct 5, 2026
d4a4c2a
Bound reviewed Dapper save contention retries with SQLite and Postgre…
sfmskywalker Oct 5, 2026
b13b512
Record bounded retry source receipt and regression evidence
sfmskywalker Oct 5, 2026
534b6bf
Preserve bounded save retry source history after mapped verification
sfmskywalker Oct 5, 2026
e189390
[skip ci] Bound Dapper save retries under sustained concurrent change…
sfmskywalker Oct 5, 2026
65b5e41
Preserve accepted Extensions bounded retry main history
sfmskywalker Oct 5, 2026
b43a17a
Record accepted bounded retry source and final verification checkpoints
sfmskywalker Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
489 changes: 489 additions & 0 deletions doc/integration-program/extensions-catchup-dispositions.json

Large diffs are not rendered by default.

43 changes: 43 additions & 0 deletions doc/integration-program/extensions-catchup.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
# Extensions release reconciliation and Core catchup

Tracker: Elsa Core #8623. The reconciled Extensions source preserves both original parents through a normal merge of release/3.9 into main. The subsequent cleanup removes one duplicate Dapper friend-assembly item introduced by the automatic project merge.

Source main: `98a185a303b6c96347d25c780528ce37f2f864a3`.
Release/3.9: `89d4eb9b739ae135604aac2a1de18653a289bdb0`.
Reconciled source: `b76f8fd216fdc529d41fbf39fd712d3fcd4e80fd`.
Previous imported source: `3cf502955791cbd20375022ef4597f0e195faf8a`.
Core mapping base: `91a1c0723`.

All stable 3.8 tags (3.8.0, 3.8.1, 3.8.2, 3.8.4), their release branch tips, and release/3.9 are ancestors of the reconciled source. No 3.8.3 tag exists in the inspected source repository. Main's package workflow and Directory.Build.props are unchanged, retaining base_version 3.10.0 and Elsa dependencies 3.10.0-preview.5760 / Studio 3.10.0-preview.1799.

## Source conflict dispositions

| Conflict path | Resolution |
| --- | --- |
| .github/workflows/packages.yml | Keep main publication settings and 3.10 base version. |
| Directory.Build.props | Keep main 3.10 preview dependency pins. |
| Dapper Modules/Runtime/Stores/KeyValueStore.cs | Keep main atomic delete method and preview-compatible documentation. |
| MongoDb Modules/Runtime/KeyValueStore.cs | Keep main scoped atomic delete method and preview-compatible documentation. |
| MongoDb Modules/Management/WorkflowInstanceStore.cs | Apply release scoped interruption through MongoDbStore.UpdateOneAsync while retaining finished-row refusal. |
| Elsa.Dapper.UnitTests/DapperWorkflowInstanceStoreTests.cs | Combine release cutoff/filter cases with main stronger cross-tenant regression and parameterized tenant seed helper. |
| Elsa.MongoDb.UnitTests/MongoKeyValueStoreTryDeleteTests.cs | Keep main concrete-store calls and deterministic historical race baseline compatible with source preview dependency. |
| Elsa.MongoDb.UnitTests/MongoWorkflowInstanceStoreTests.cs | Keep main exact recursive Id-filter assertions. |
| Elsa.Persistence.Dapper.UnitTests/DapperKeyValueStoreTryDeletePostgreSqlTests.cs | Keep main concrete-store coverage against migration-built PostgreSQL. |
| Elsa.Persistence.Dapper.UnitTests/DapperKeyValueStoreTryDeleteTests.cs | Keep main concrete-store and SQLite race baseline coverage. |
| Elsa.Persistence.Dapper.UnitTests/DapperPostgreSqlMigrationTests.cs | Include release BeforeLastUpdated coverage. |
| Elsa.Persistence.Dapper.UnitTests/NonPgQuerySqlSnapshotTests.cs | Include release exclusive less-than snapshots. |
| Elsa.Persistence.Dapper.UnitTests/PostgreSqlDialectTests.cs | Include release quoted less-than assertions. |

## Core mapping

`extensions-catchup-dispositions.json` accounts for every changed source path using the established destination mapping in `scripts/integration-program/rehearse-import.py`. Root-level settings, workflows, solution metadata, and instructions are refreshed only as inert `.source` snapshots. Current Core build/publication configuration remains authoritative.

The live slice adds the existence-guarded Dapper runtime migration 20008 (KeyValues and BookmarkQueueItems.SerializedOptions), atomic tenant-scoped TryDelete implementations, default-tenant NULL/empty compatibility, corrected prefix parameter binding, BeforeLastUpdated filtering, Mongo interruption/summary tenant scoping, DI-backed variable serialization, and JsonNode subtype/legacy compatibility. Imported regression coverage exercises migration-built SQLite/PostgreSQL and MongoDB containers. Core atomic-delete tests dispatch through IKeyValueStore because Core already supplies that API.

Existing Core project-reference/SSH.NET compatibility adjustments and MigrationDatabases.QuotedIdentifiers/UnquotedIdentifiers are preserved. Identity V3_10 remains untouched. Files already equal to the reconciled source are recorded without rewriting them.

Verification is recorded by the integrating lead after source and mapped Core test execution. No publication or cutover is performed by this local slice.

## Persistence review follow-up

[Extensions #286](https://github.com/elsa-workflows/elsa-extensions/pull/286) at `8626e81f4a780be7d5fde87a1ae8b15cc6915934` adds reviewed ownership-safe saves, literal prefix semantics, SQLite instant comparison, and legacy Mongo envelope-collision handling. The refreshed receipt includes all 48 paths from the previous imported source through this follow-up. Core keeps its documented API/layout adaptations. Full source and mapped persistence suite evidence is recorded in [the catch-up verification report](release-catchup-verification.md).
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Advisory PR reviewers

Live list of automated reviewers for this repository (elsa-extensions). Agents read it before opening a PR.

Last verified: 2026-10-04

| Reviewer | Status | How to request | Notes |
| --- | --- | --- | --- |
| GitHub Copilot code review (`copilot-pull-request-reviewer[bot]`) | live | Add reviewer `@copilot`: `gh pr edit <n> --add-reviewer @copilot` (GitHub CLI 2.88 or later) | Advisory. A `@copilot review` comment does not trigger it. Bot-authored PRs need the org policy that lets Copilot review them. |
| Greptile (`greptile-apps[bot]`) | not live | Comment `@greptileai` (once enabled here) | Advisory; not part of the merge gate (see Rules). Installed, but does not review PRs here. |
| CodeRabbit (`coderabbitai[bot]`) | not live | Comment `@coderabbitai review` (once enabled here) | Not enabled for this repository. |
| Cursor Bugbot | not live | Top-level PR comment `cursor review` (once enabled) | Must first be enabled in the Cursor dashboard. `cursor[bot]` comments on PRs come from Cursor cloud agents, not Bugbot. |
| GitHub Code Quality (`github-code-quality[bot]`) | informational | Automatic; cannot be requested | CodeQL code-quality comments. Not an advisory pick and not part of the merge gate. |

## Rules

- Greptile does not review PRs on this repository. Do not wait for or request a Greptile score.
- Pick exactly one live advisory reviewer from the table (currently Copilot) and request it once the PR is open. Do not request a second reviewer.
- If the picked reviewer declines or skips the PR, request another live reviewer if there is one; otherwise continue without one.
- The PR author (human or agent) never reviews or approves its own PR.
- Merge gate: the only merge gate is an Elsa 3 Code Review on the PR whose body starts with the line `Elsa 3 Code Review: APPROVE + HIGH @ <head sha>` (the full 40-character SHA of the PR's current head commit), plus green CI on that head. The Code Review is posted as `sfmskywalker` with review event COMMENT, so its GitHub review state is COMMENTED, not APPROVED. A `REQUEST_CHANGES` verdict, a confidence below `HIGH`, or a SHA other than the current head does not pass. The Code Review is a separate reviewer from the PR author, even when both post from the same account.
- Pin the merge to the approved SHA: `gh pr merge <n> --match-head-commit <sha>`, or the merge API (`PUT /repos/{owner}/{repo}/pulls/{n}/merge`) with `sha=<sha>`. Any push after the approval voids it; Code Review must re-confirm with `Elsa 3 Code Review: APPROVE + HIGH @ <new head sha>` before merging.
- Greptile, CodeRabbit, Copilot and Bugbot are advisory only. Their findings feed into the Code Review, but none of them is required for merge: there is no Greptile score gate (no 5/5 requirement) and no waive process.
- Update this file whenever a reviewer is added, removed, or changes how it is requested.
Original file line number Diff line number Diff line change
@@ -1,6 +1,16 @@
name: Packages
on:
workflow_dispatch:
inputs:
# Does nothing on main while base_version is 3.10.x. Dispatch VERSION is
# always ${base_version}-${prefix}.${run_number}, so the nuget.org job's
# !startsWith(..., '3.10.') gate never opens. Publishing 3.10 publicly
# later means deliberately removing that check and deciding how a dispatch
# run sets VERSION.
publish_nuget:
description: 'Publish packages to nuget.org (never for 3.10.x)'
type: boolean
default: false
push:
branches:
- 'main'
Expand All @@ -26,6 +36,8 @@ jobs:
name: Build packages
runs-on: ubuntu-latest
timeout-minutes: 30
outputs:
version: ${{ steps.set_version.outputs.version }}
steps:
- name: Extract branch name
run: |
Expand Down Expand Up @@ -56,13 +68,17 @@ jobs:
git branch --remote --contains | grep origin/${BRANCH_NAME}
fi
- name: Set VERSION variable
id: set_version
run: |
if [[ "${{ github.ref }}" == refs/tags/* && "${{ github.event_name }}" == "release" && ("${{ github.event.action }}" == "published" || "${{ github.event.action }}" == "prereleased") ]]; then
TAG_NAME=${{ github.ref }} # e.g., refs/tags/3.0.0
TAG_NAME=${TAG_NAME#refs/tags/} # remove the refs/tags/ prefix
echo "VERSION=${TAG_NAME}" >> $GITHUB_ENV
echo "version=${TAG_NAME}" >> $GITHUB_OUTPUT
else
echo "VERSION=${{env.base_version}}-${PACKAGE_PREFIX}.${{github.run_number}}" >> $GITHUB_ENV
VERSION="${{env.base_version}}-${PACKAGE_PREFIX}.${{github.run_number}}"
echo "VERSION=${VERSION}" >> $GITHUB_ENV
echo "version=${VERSION}" >> $GITHUB_OUTPUT
fi
- uses: actions/setup-dotnet@v5
with:
Expand All @@ -77,7 +93,7 @@ jobs:
with:
name: elsa-nuget-packages
path: packages/*nupkg
if: ${{ github.event_name == 'release' || github.event_name == 'push'}}
if: ${{ github.event_name == 'release' || github.event_name == 'push' || github.event_name == 'workflow_dispatch'}}

publish_preview_feedz:
name: Publish to feedz.io
Expand All @@ -91,15 +107,30 @@ jobs:
with:
name: elsa-nuget-packages

- name: Check API key (feedz.io)
env:
API_KEY: ${{ secrets.FEEDZ_API_KEY }}
run: |
if [ -z "$API_KEY" ]; then
echo "::error::API key for feedz.io is empty. Check the FEEDZ_API_KEY repository secret; nothing was pushed."
exit 1
fi

- name: Publish to feedz.io
run: dotnet nuget push *.nupkg -k ${{ secrets.FEEDZ_API_KEY }} -s ${{ env.feedz_feed_source }} --skip-duplicate
env:
API_KEY: ${{ secrets.FEEDZ_API_KEY }}
run: dotnet nuget push *.nupkg -k "$API_KEY" -s ${{ env.feedz_feed_source }} --skip-duplicate

publish_nuget:
name: Publish release to nuget.org
needs: build
runs-on: ubuntu-latest
timeout-minutes: 20
if: ${{ github.event_name == 'release' && github.event.action == 'published' }}
# Dispatch-only. 3.10.x (including 3.10.0-preview.*) must never reach nuget.org.
# publish_nuget does nothing on main while base_version is 3.10.x. Publishing
# 3.10 publicly later means deliberately removing the 3.10. check and deciding
# how a dispatch run sets VERSION (always base_version-prefix.run_number).
if: ${{ github.event_name == 'workflow_dispatch' && inputs.publish_nuget && !startsWith(needs.build.outputs.version, '3.10.') }}
permissions:
# Required to request the OIDC token that nuget.org exchanges for a short-lived API key (Trusted Publishing).
id-token: write
Expand All @@ -116,5 +147,16 @@ jobs:
with:
user: ${{ env.nuget_user }}

- name: Check API key (nuget.org)
env:
API_KEY: ${{ steps.nuget_login.outputs.NUGET_API_KEY }}
run: |
if [ -z "$API_KEY" ]; then
echo "::error::API key for nuget.org is empty. Check the NuGet login (OIDC) step output and the Trusted Publishing policy on nuget.org; nothing was pushed."
exit 1
fi

- name: Publish to nuget.org
run: dotnet nuget push *.nupkg -k ${{ steps.nuget_login.outputs.NUGET_API_KEY }} -s ${{ env.nuget_feed_source }} --skip-duplicate
env:
API_KEY: ${{ steps.nuget_login.outputs.NUGET_API_KEY }}
run: dotnet nuget push *.nupkg -k "$API_KEY" -s ${{ env.nuget_feed_source }} --skip-duplicate
3 changes: 3 additions & 0 deletions doc/integration-program/legacy/extensions/AGENTS.md.source
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# AGENTS.md

Before opening a PR, read `.github/reviewers.md` and request exactly one live advisory reviewer from it once the PR is open. Greptile does not review PRs here, and all automated reviewers are advisory; merge only on the gate described there (Elsa 3 Code Review `APPROVE + HIGH @ <head sha>` plus green CI, merge pinned to that SHA).
Original file line number Diff line number Diff line change
Expand Up @@ -37,8 +37,8 @@
</PropertyGroup>

<PropertyGroup Label="PackageVersions">
<ElsaVersion>3.10.0-preview.5705</ElsaVersion>
<ElsaStudioVersion>3.10.0-preview.1749</ElsaStudioVersion>
<ElsaVersion>3.10.0-preview.5760</ElsaVersion>
<ElsaStudioVersion>3.10.0-preview.1799</ElsaStudioVersion>
</PropertyGroup>

</Project>
Original file line number Diff line number Diff line change
Expand Up @@ -165,6 +165,9 @@
<PackageVersion Include="FluentMigrator" Version="7.2.0"/>
<PackageVersion Include="FluentMigrator.Runner" Version="7.2.0"/>
<PackageVersion Include="FluentMigrator.Runner.Core" Version="7.2.0"/>
<PackageVersion Include="FluentMigrator.Runner.MySql" Version="7.2.0"/>
<PackageVersion Include="FluentMigrator.Runner.Oracle" Version="7.2.0"/>
<PackageVersion Include="FluentMigrator.Runner.Postgres" Version="7.2.0"/>
<PackageVersion Include="FluentMigrator.Runner.SqlServer" Version="7.2.0"/>
<PackageVersion Include="FluentMigrator.Runner.SQLite" Version="7.2.0"/>
<PackageVersion Include="FluentStorage" Version="6.0.0"/>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -336,6 +336,10 @@ Project("{2150E333-8FDC-42A3-9474-1A3956D46DE8}") = "runtimes", "runtimes", "{74
EndProject
Project("{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}") = "Elsa.Workflows.Runtime.ProtoActor.UnitTests", "test\modules\runtimes\Elsa.Workflows.Runtime.ProtoActor.UnitTests\Elsa.Workflows.Runtime.ProtoActor.UnitTests.csproj", "{209765CA-207B-44F0-94E4-0711235E7F99}"
EndProject
Project("{2150E333-8FDC-42A3-9474-1A3956D46DE8}") = "secrets", "secrets", "{A1526B50-A5D1-398B-3070-5440A8E5BDFE}"
EndProject
Project("{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}") = "Elsa.Secrets.Management.UnitTests", "test\modules\secrets\Elsa.Secrets.Management.UnitTests\Elsa.Secrets.Management.UnitTests.csproj", "{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}"
EndProject
Global
GlobalSection(SolutionConfigurationPlatforms) = preSolution
Debug|Any CPU = Debug|Any CPU
Expand Down Expand Up @@ -1610,6 +1614,18 @@ Global
{C115D266-ED50-4584-B059-B4BB48B54C77}.Release|x64.Build.0 = Release|Any CPU
{C115D266-ED50-4584-B059-B4BB48B54C77}.Release|x86.ActiveCfg = Release|Any CPU
{C115D266-ED50-4584-B059-B4BB48B54C77}.Release|x86.Build.0 = Release|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Debug|Any CPU.ActiveCfg = Debug|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Debug|Any CPU.Build.0 = Debug|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Debug|x64.ActiveCfg = Debug|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Debug|x64.Build.0 = Debug|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Debug|x86.ActiveCfg = Debug|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Debug|x86.Build.0 = Debug|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Release|Any CPU.ActiveCfg = Release|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Release|Any CPU.Build.0 = Release|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Release|x64.ActiveCfg = Release|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Release|x64.Build.0 = Release|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Release|x86.ActiveCfg = Release|Any CPU
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F}.Release|x86.Build.0 = Release|Any CPU
EndGlobalSection
GlobalSection(SolutionProperties) = preSolution
HideSolutionNode = FALSE
Expand Down Expand Up @@ -1758,6 +1774,8 @@ Global
{799D5262-2BB1-C4D2-CB3D-522B0B7186CF} = {3DDE6F89-531C-47F8-9CD7-7A4E6984FA48}
{1994376D-9775-4709-88E5-BE44618546AD} = {799D5262-2BB1-C4D2-CB3D-522B0B7186CF}
{C115D266-ED50-4584-B059-B4BB48B54C77} = {273F8587-516E-41F3-93B9-D2F8FDC188A4}
{A1526B50-A5D1-398B-3070-5440A8E5BDFE} = {3DDE6F89-531C-47F8-9CD7-7A4E6984FA48}
{02CB40E6-1DC0-4AC8-B9F1-D268CA26654F} = {A1526B50-A5D1-398B-3070-5440A8E5BDFE}
EndGlobalSection
GlobalSection(ExtensibilityGlobals) = postSolution
SolutionGuid = {11A771DA-B728-445E-8A88-AE1C84C3B3A6}
Expand Down
23 changes: 23 additions & 0 deletions doc/integration-program/legacy/studio/.github/reviewers.md.source
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# Advisory PR reviewers

Live list of automated reviewers for this repository (elsa-studio). Agents read it before opening a PR.

Last verified: 2026-10-04

| Reviewer | Status | How to request | Notes |
| --- | --- | --- | --- |
| Greptile (`greptile-apps[bot]`) | live | Automatic when a PR is opened; comment `@greptileai` to review a new head after a push | Advisory; not part of the merge gate (see Rules). Posts a "Confidence Score: N/5" summary and a "Greptile Review" check. Reviews only allow-listed authors; others get "PR author is not in the allowed authors list". |
| CodeRabbit (`coderabbitai[bot]`) | live | Automatic on PRs into `main`; comment `@coderabbitai review` for other base branches or a re-review after a push | Advisory. Skips PRs into other base branches unless requested. Reviews draw on an hourly allowance, so do not request it while its automatic review is pending. |
| GitHub Copilot code review (`copilot-pull-request-reviewer[bot]`) | live | Add reviewer `@copilot`: `gh pr edit <n> --add-reviewer @copilot` (GitHub CLI 2.88 or later) | Advisory. A `@copilot review` comment does not trigger it. Bot-authored PRs need the org policy that lets Copilot review them. |
| Cursor Bugbot | not live | Top-level PR comment `cursor review` (once enabled) | Must first be enabled in the Cursor dashboard. `cursor[bot]` comments on PRs come from Cursor cloud agents, not Bugbot. |

## Rules

- Greptile reviews automatically when a PR is opened. It is advisory: after a push you may comment `@greptileai` for a fresh review of the new head, but nobody waits for a Greptile score.
- Besides Greptile, request at most one additional advisory reviewer (CodeRabbit or Copilot) once the PR is open. If your pick reviews automatically on this PR (CodeRabbit does on PRs into `main`), wait for that run instead of requesting it; request it manually only if no run appears, the PR targets another base branch, or you need a re-review after a push.
- If the additional reviewer declines or skips the PR, you may request the other one instead.
- The PR author (human or agent) never reviews or approves its own PR.
- Merge gate: the only merge gate is an Elsa 3 Code Review on the PR whose body starts with the line `Elsa 3 Code Review: APPROVE + HIGH @ <head sha>` (the full 40-character SHA of the PR's current head commit), plus green CI on that head. The Code Review is posted as `sfmskywalker` with review event COMMENT, so its GitHub review state is COMMENTED, not APPROVED. A `REQUEST_CHANGES` verdict, a confidence below `HIGH`, or a SHA other than the current head does not pass. The Code Review is a separate reviewer from the PR author, even when both post from the same account.
- Pin the merge to the approved SHA: `gh pr merge <n> --match-head-commit <sha>`, or the merge API (`PUT /repos/{owner}/{repo}/pulls/{n}/merge`) with `sha=<sha>`. Any push after the approval voids it; Code Review must re-confirm with `Elsa 3 Code Review: APPROVE + HIGH @ <new head sha>` before merging.
- Greptile, CodeRabbit, Copilot and Bugbot are advisory only. Their findings feed into the Code Review, but none of them is required for merge: there is no Greptile score gate (no 5/5 requirement) and no waive process.
- Update this file whenever a reviewer is added, removed, or changes how it is requested.
Loading
Loading