Repository navigation
Conversation
…ility (conductor-oss#1537) bump springdoc to 2.8.6 for Spring Framework 6.2 compatibility
…conductor-oss#1494) * - Add end to end integration tests - Update playwright so it can get OPENAI_API_KEY from .env.local * Bump coverage percentage to 90% to test CI before merging in additional tests * Update workflow to use coverage report script * Add tests and remove kitchen * - Delete orphaned components - Cleanup local coverage runs * Make test less flaky * Run integration tests in docker for consistent snapshots * Show incompletion reasons --------- Co-authored-by: Dale Brady <49766562+bradyyie@users.noreply.github.com>
* conductor-oss#1489 Fix incorrect conductor version when app is loading * Capitalize Unknown
…nch is canceled (conductor-oss#1425) * fix: propagate CANCELED instead of FAILED from JOIN when a forked branch is canceled * test: cover permissive fork join sub workflows terminated by the user in the test harness --------- Co-authored-by: Naomi Most <naomi.most@orkes.io>
…0.56.0 (conductor-oss#1541) * Fix monaco editor context menu paste by forcing loader to use monaco 0.56.0 * Extract to a side-effect module * Make test less flaky
mkdocs.yml declares the mermaid custom fence as
`!!python/name:main.mermaid_fence`, which PyYAML resolves with a plain
`import main` while parsing the config. The deploy action runs the mkdocs
console script inside a Docker container, where sys.path[0] is the script's
bin directory rather than the checkout, so the import fails and the deploy
aborts before building.
Point PYTHONPATH at the container's workspace mount so main.py resolves.
Run 32411004435 failed with:
cannot find module 'main' (No module named 'main')
in "/github/workspace/mkdocs.yml", line 283, column 19
- new step in publish.yml points the conductor-oss org's CONDUCTOR_SERVER_VERSION variable at the just-published version - runs after Maven Central publish succeeds, covers RC and stable releases - org variable falls back for java-sdk, javascript-sdk, python-sdk, csharp-sdk e2e workflows without a per-repo write
Workflow diagram 'Export to image' has multiple issues (unresponsive, draft export fails, switch node unreadable)
* https://orkes.atlassian.net/browse/CCOR-13363 Improve Queue Monitor filter UX * Don't make so many fetches when using queue monitor quick search * Avoid using sx unless it's for overrides * Update tests
…ent returnStrategy options (conductor-oss#1579)
Import BPMN feature is not easily discoverable on Workflow Definitions page
* fix(ui): schedule search API, overwrite on edit, and self-contained clone dialog Use /scheduler/schedules/search for schedule lists; overwrite=true on edit saves; clone dialog owns the save mutation and handles 409 via form state. Migrate schedulerHooks to TypeScript. * Instead of fetching all schedules for the clone dialog, check for existing schedule when doing clone save * Use shorter error message * https://orkes.atlassian.net/browse/CCOR-12995 Add colors for new Schedule manager role * - Update roles to use lookup for colors instead of if statements - Convert orkes-theme to ts and simplify to use hex colors - Remove unused globalConstants
…letion (conductor-oss#1596) * Docs: describe the current Executions search UI and document reasonForIncompletion * Docs: drop the localhost link from the Executions search step
Co-authored-by: Naomi Most <naomi.most@orkes.io>
Adds support for schema registry to workflows and tasks.
…ductor-oss#1528) (conductor-oss#1598) * fix(deps): bump netty to 4.1.136.Final and micrometer to 1.15.12 (conductor-oss#1528) Resolves the remaining high-severity Java CVEs flagged in conductor-oss#1528: - netty 4.1.135.Final -> 4.1.136.Final CVE-2026-56819 (netty-codec-http2), CVE-2026-55831/55833/56745 (netty-codec-http), CVE-2026-59901 (netty-codec) - micrometer-core 1.15.11 -> 1.15.12 via revMicrometer + a BOM override CVE-2026-40983, CVE-2026-40984 micrometer-core was resolved to 1.15.11 by the Spring Boot BOM while the explicitly-declared registry artifacts were pinned at revMicrometer=1.14.6. Bumping revMicrometer to 1.15.12 and adding ext['micrometer.version'] = revMicrometer keeps core and the registries aligned on the patched version. * fix(deps): keep micrometer registries on 1.14.6 to preserve protobuf 3.x Bumping the whole micrometer family to 1.15.12 pulled micrometer-registry-otlp 1.15.x, which brings opentelemetry-proto 1.5.0-alpha. That gencode requires protobuf-java 4.x (com.google.protobuf.RuntimeVersion$RuntimeDomain), but protobuf-java is pinned to 3.25.5 (conductor-oss#964, GraalVM), so OtlpMeterRegistry failed at runtime with NoClassDefFoundError and OtlpMetricsConfigurationTest broke. Decouple the versions: micrometer-core still bumps to 1.15.12 (the CVE fix, via the BOM property), while the registry artifacts (otlp/cloudwatch2/azure-monitor/ prometheus) stay on 1.14.6 -> opentelemetry-proto 1.3.2-alpha (protobuf 3.x). This matches the working main baseline for the registries.
…o sentinels by default (conductor-oss#1578) * feat(redis-sentinel): add conductor.redis.sentinelPassword, no AUTH to sentinels by default Sentinels without requirepass reject AUTH (Jedis 6 has no tolerance for the error reply). Gate sentinel credentials behind an explicit property, matching Spring/Lettuce sentinel.password semantics. Master auth still comes from the 4th segment of conductor.redis.hosts. * docs(redis-configuration): document sentinel-password, fix stale sentinel auth description - Rewrite the RedisSentinelConfiguration bullet that still described the pre-conductor-oss#1578 behavior (sentinels reusing the data-node password) - Add sentinel-password row to the connection properties table - Show the property in the Sentinel quick-start example - Correct ignore-ssl scope: honored in cluster and sentinel modes, not cluster only (verified against createBaseClientConfigBuilder) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: jrnie <jrnie@iflytek.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Viren Baraiya <virenx@gmail.com> Co-authored-by: Naomi Most <naomi.most@orkes.io>
…rkflow should show it in prompt template and not text in custom instructions (conductor-oss#1652) * https://orkes.atlassian.net/browse/CCOR-13507 LLM Chat complete task that uses AI Prompt in a saved workflow should show it in prompt template and not text in custom instructions * xstate machine should not be using useEffects
Add LLM Recording/Playback Functionality (conductor-oss#1614) Used for recording how agent execution went via a given SDK, and then ensuring that another SDK runs the exact same way
…er an hour (conductor-oss#1615) (conductor-oss#1655) * fix(core): retry a stranded SUB_WORKFLOW instead of timing it out after an hour (conductor-oss#1615) A worker that dies inside SubWorkflow.start() leaves the task SCHEDULED with its message reserved for responseTimeout (TaskDef.ONE_HOUR by default). Repair skips it because the message is present-but-invisible, and on redelivery the executor force-sets TIMED_OUT instead of re-running start(), so the child is never created and the workflow times out. Don't time out a redelivered SCHEDULED task when start() is idempotent, and size its reserve from the system task callback interval rather than responseTimeout. Recovery drops from ~60min to ~60s; non-idempotent tasks are unchanged, so conductor-oss#1321 is unaffected. * style(core): name the short-reserve multiplier Extract the bare 2 in reserveSeconds() into SHORT_RESERVE_CALLBACKS with a comment on why the short reserve is sized this way. No behavior change -- the reserve is still 2 x systemTaskCallbackTime. --------- Co-authored-by: Naomi Most <naomi.most@orkes.io>
…ctor-oss#1534) (conductor-oss#1653) Spring Boot 3.5.14's OtlpMetricsExportAutoConfiguration builds the registry via OtlpMeterRegistry.builder(...), a class that only exists from micrometer-registry-otlp 1.15.0. The registries were pinned to 1.14.6, so enabling management.otlp.metrics.export.enabled=true crashed the server at startup with: NoClassDefFoundError: io/micrometer/registry/otlp/OtlpMeterRegistry$Builder Bump revMicrometerRegistry 1.14.6 -> 1.15.12 (matching revMicrometer) so the Builder is present. The registries were held at 1.14.6 because micrometer-registry-otlp 1.15.x requests opentelemetry-proto 1.5.0-alpha, whose generated code needs protobuf-java 4.x — but protobuf is pinned to 3.x (conductor-oss#964, GraalVM polyglot). Force opentelemetry-proto back to 1.3.2-alpha (protobuf 3.x, GeneratedMessageV3) to keep the 3.x stack: micrometer 1.15's OTLP serializer references only metrics/common/resource proto messages, all present in 1.3.2-alpha; the only delta to 1.5.0-alpha is profiling classes micrometer never touches. Rewrite OtlpMetricsConfigurationTest to drive Spring Boot's actual OtlpMetricsExportAutoConfiguration (with management.otlp.metrics.export .enabled=true) instead of hand-constructing the registry, so it exercises the code path that regressed. The test fails on 1.14.6 with the exact NoClassDefFoundError above and passes on 1.15.12.
…onductor-oss#1657) * [CCOR-13431]enh(clone): allow clone dialog to offer a source version * ref(clone): treat clone versions as final on open
…inear scanner (conductor-oss#1654) The pattern used to find ${...} expressions relied on nested lookaheads and backreferences. It is applied to every string task parameter, including task output returned by workers, and its matching time grows polynomially with the nesting depth: ${${...}} nested 1000 deep (~3 KB) takes over 30 seconds. Find the expressions with a single pass that tracks the brace depth instead. The semantics are unchanged, including $${ escaping, nested expressions and an unclosed expression hiding the rest of the string; a test compares the scanner with the previous pattern on every string of a small alphabet up to length 6. Fixes conductor-oss#1638 Co-authored-by: Naomi Most <naomi.most@orkes.io>
…th helper (Fixes conductor-oss#1642) (conductor-oss#1660) The .replace(/\]\[/g, "][") at helpers.ts:194 replaced "][" with itself, a no-op flagged by CodeQL (js/identity-replacement, alert conductor-oss#23). It carried the comment "Clean up any double brackets that might have been created", but adjacent brackets like "[0][1]" are valid lodash nested-access syntax and are exactly what the downstream lodash/fp/path consumer expects. The cleanup it implied was never needed, and the line never changed anything -- all existing tests pass with it removed. Removed the dead replacement and clarified the comment. Added tests covering markers sitting directly between brackets (the case the line pretended to guard) plus the empty/undefined path cases.
…nductor-oss#1513) (conductor-oss#1647) Co-authored-by: Naomi Most <naomi.most@orkes.io>
* feat(ui-next): add subAgentCount and replaceAgentRunNode for lazy sub-agent expansion (conductor-oss#1452) * feat(ui-next): wire lazy sub-agent expansion into AgentExecutionTab and AgentRunView (conductor-oss#1452) * fix(ui-next): recurse into expanded sub-agents in Execution diagram, add Expand control (conductor-oss#1452) * fix(ui-next): sort executions by workflowType, not workflowName (conductor-oss#1514) Sort column was remapped to a nonexistent workflowName field, which no backend indexes, so ASC/DESC returned rows in the same order. --------- Co-authored-by: meghana21-arch <saimeghana.barla@gmal.com> Co-authored-by: Naomi Most <naomi.most@orkes.io>
…#1672) ws 7.5.8 (via jsdom) and 8.8.0 (via webpack-dev-server) are both below the CVE-2024-37890 fix. Both are transitive dev-only dependencies, so pin them up via yarn resolutions rather than a direct dependency: jsdom/ws -> ^7.5.10 (backport fix, stays on the 7.x line jsdom expects) webpack-dev-server/ws -> ^8.17.1 Resolves to ws 7.5.13 and 8.21.3, both above the patched thresholds. Fixes conductor-oss#643
…onductor-oss#1656) * [CCOR-13476]enh(grpc): add compression codec field to GRPC task form * [CCOR-13476]test(grpc): cover the compression codec field --------- Co-authored-by: Naomi Most <naomi.most@orkes.io>
…ss#1651) * Prevent path traversal in DummyPayloadStorage DummyPayloadStorage resolved the caller-supplied path against payloadDir with no validation, in both upload() and download(): File file = new File(payloadDir, path); return new FileInputStream(new File(payloadDir, path)); so a "../"-style path could read or write outside the payload directory. This is the default payload storage when no external storage (S3/GCS) is configured, so it is reachable in dev and default deployments. Mirrors the fix merged for MockExternalPayloadStorage in conductor-oss#723: a private validateAndResolvePath() that normalizes the path, rejects a normalized path still containing "..", and verifies the canonical path stays within payloadDir, throwing SecurityException on escape. Both call sites route through it and catch, so the existing contract is unchanged - download() still returns null on failure rather than propagating. Adds tests for traversal on both read and write paths, and for a nested path, which also covers the parent-directory creation the shared pattern relies on. Closes conductor-oss#1639 * test: assert upload traversal never writes outside payloadDir; close payload on rejection The upload-traversal test previously asserted only that download() of the same "../" path returned null -- but download() rejects any "../" path regardless of whether a file exists, so the test passed even if upload() had written outside payloadDir. It now asserts directly on disk that the escaped file was never created, via a package-private getPayloadDir() seam. Also restructures upload() so the payload InputStream is always closed, including when validateAndResolvePath() rejects the path -- previously the stream leaked on the rejection branch because the close lived in an inner finally that validation skipped past. --------- Co-authored-by: Naomi Most <naomi.most@orkes.io>
defaultShowColumns listed "cronTabExpression", but the column id is "cronExpression", so the column was hidden unless enabled manually. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Naomi Most <naomi.most@orkes.io>
Extract defaultShowColumns into getDefaultShowColumns() and assert every id it lists matches a real column, so a typo like "cronTabExpression" can't silently hide a column again. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
conductor-oss#1699) * DateRange picker styling is misaligned and dates are not visible on hover https://orkes.atlassian.net/browse/CCOR-13545 * Consolidate date picker
conductor-oss#1697) * [CCOR-13544] Restore task execution search functionality in the new UI https://orkes.atlassian.net/browse/CCOR-13544 * [CCOR-13544] Restore task execution search functionality in the new UI https://orkes.atlassian.net/browse/CCOR-13544
…ule-list-cron-column fix(ui): show the cron expression column by default in the schedule list
…-link-for-task-input-template
…un-agent-panel-error-detail [CCOR-13377]fix(agent): show why the agent failed to start
…-link-for-task-input-template
…ask-definition-remove-learn-more-link-for-task-input-template [CCOR-13510]fix(task-def): drop the dead input template docs link
…nSensor fork - dependencies.gradle, ChatMessage.java, ui-next tests: upstream versions - es8-persistence journal request identities (fork) kept over upstream's plain client calls Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merge of upstream conductor-oss/conductor main (ab2de6d, 2026-10-02) into the fork.
Conflicts resolved:
Opened as a draft so ci.yml validates the merge before anything reaches a generation image.
🤖 Generated with Claude Code