Skip to content

Bump @paperclipai/plugin-sdk from 2026.817.0 to 2026.916.1 - #11

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/paperclipai/plugin-sdk-2026.916.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/paperclipai/plugin-sdk-2026.916.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown

Bumps @paperclipai/plugin-sdk from 2026.817.0 to 2026.916.1.

Release notes

Sourced from @​paperclipai/plugin-sdk's releases.

v2026.916.1

Paperclip v2026.916.1

Released: 2026-09-21

A patch on top of 2026.916.0 that fixes sending messages in the task conversation view. It carries one targeted fix (plus its regression tests and a small server error-classification repair that rode along in the same commit); everything else in 2026.916.0 is unchanged.

Fixes

  • The chat composer's send button no longer starts out disabled on desktop. The task page disables the composer while it checks whether the task is paused, and in React Query v5 that pending state is true from mount until the first successful response — so every desktop task page loaded with the send button disabled, and it stayed disabled for good if the pause-status request stalled. Sends are now allowed while the check is pending: the server remains authoritative and rejects messages to paused tasks with a 409 before saving a comment or waking an agent, and a confirmed pause hold or a failed status check still blocks the composer as before. (#13562)
  • Duplicate document inserts wrapped by the ORM are classified as retryable conflicts again, instead of surfacing as opaque database errors; unrelated database failures keep their original identity. (Part of #13562)

Upgrade Guide

  • No migrations, no configuration changes, no API changes. Upgrade in place.

v2026.916.0

Paperclip v2026.916.0

Released: 2026-09-16

Paperclip v2026.916.0 carries 503 commits, promoted from 2026.916.0-beta.0 published the same day. The headline is the Connections train: AI runtime credentials — Claude and Codex subscriptions, API keys, shared accounts — now live in Connections under the same grants and permission boundaries as every other account, follow the responsible person through hiring and task execution, and can be connected or repaired inline from the task that needs them. Around it: agents get their own email addresses through AgentMail, experimental chat connectors bring Slack, Discord, Telegram, Microsoft Teams, and (via Photon) iMessage conversations into tasks, GitHub access becomes durable per-person identities instead of one shared token, announcements arrive as native in-app cards, and the experimental Paperclip Runner grew from last release's groundwork into a complete execution engine — with the gate now open by default on self-hosted installs for explicitly configured agents.

Breaking Changes

  • Cheap model profiles are removed. The second execution mode that let recovery and overrides run on a cheaper model is gone from adapter metadata, agent runtime configuration, task overrides, recovery rules, the APIs, and the board UI; migration 0236 strips stored modelProfiles blocks from agent configurations. There is now one model-selection path for normal work and recovery work. (#12683)
  • Agent APIs no longer return plaintext credentials. Every endpoint that serializes an agent — detail reads, the company agent list, and create/update/lifecycle routes — used to echo adapterConfig.env as stored, so plain bindings (API keys, tokens) came back verbatim to any caller able to read the agent, including the agent itself via GET /api/agents/me. All three response families now route through one redacting presenter. Integrations that scraped live credentials out of those responses will stop working — that was the leak. (#9860, @​glovario)
  • Automatic productivity reviews are retired. The detector that turned run counts, comment counts, and elapsed time into management-review tasks is deleted along with its continuation holds — infrastructure failures could satisfy its rules and manufacture work. Bounded recovery, budgets, explicit blockers, and the normal review stages all remain; existing task records stay readable and unchanged. (#13263)
  • X-Forwarded-Host is only honored from a trusted proxy. The same-origin guard used to accept a forwarded host from any direct client, letting a caller promote its own header into the trusted-origin set. The forwarded host now counts only when the immediate peer passes the operator's TRUST_PROXY setting — deployments behind a reverse proxy should confirm TRUST_PROXY is configured, or the proxy's forwarded host is ignored in favor of the raw Host header. (#12832)
  • Anthropic's legacy REST connection option is gone, and REST tool connections are validated as REST. The obsolete REST setup path is removed in favor of the supported AI-account flow, and stdio validation no longer lets an unsupported REST connection pass (or fail with a misleading templateId error) — existing unsupported connections now receive an accurate rejection. (#13346)

Highlights

  • AI credentials live in Connections now — Provider sign-ins stop being per-agent configuration and become managed accounts with the ownership, grants, and access permissions Connections already enforces: agents reuse the responsible user's account or a permitted shared one, and model/harness selection stays independent from credential selection, with legacy agents keeping their existing authentication until they explicitly adopt a managed connection (#13247). The same sign-in components are reused across onboarding, agent configuration, and the Connectors page instead of a second login wizard (#13248). Hired agents inherit the hiring agent's provider credential references so a delegated teammate can authenticate from its first run (#13268), and connections follow hires across legacy and native runners — a missing account pauses the task and offers the connection form inline instead of failing (#13438). Each responsible user gets a per-provider default, so the same agent can run on one person's subscription and another's API key (#13351). The train also hardened as it landed: subscription sign-in works on authenticated self-hosted instances without exposing the server operator's CLI account (#13344), credential leases survive transaction pooling instead of reporting a phantom "connection busy" (#13347), one Anthropic subscription connection supports concurrent runs — only file-backed credentials still serialize (#13445), and connection probes, saved-account reuse, and task handoffs got reliability passes (#13404, #13161).
  • Agents get their own email — AgentMail connections (experimental) give an agent a dedicated inbox: incoming email becomes assigned work in a task, sends are explicit agent actions authenticated through Paperclip, and internal task comments can never leak out as outgoing mail by accident. The provider key stays in the server vault, and the board follows each conversation from a task email card. (#13256)
  • Reach your agents from your chat tools — Experimental native chat connectors bind a Slack, Discord, Telegram, Microsoft Teams, or GitHub bot identity to one agent and each admitted external conversation to one task, with durable per-conversation queues, questions, progress, files, and delivery receipts — board comments stay internal unless explicitly sent to the channel, and raw reasoning, logs, and credentials are never sent at all (#13100, #13038). iMessage joins through the experimental Photon channel: shared Pro DMs or dedicated numbers, photos included, with Paperclip keeping task ownership and approval authority (#13299). In the app itself, experimental Agent Chat gives every person a persistent conversation with each agent — backed by real tasks and normal governance, not a parallel chat store — and every company agent is reachable from the Chats sidebar through a searchable picker (#13284, #13420).
  • GitHub access becomes identities, not a shared token — GitHub App-backed identities with durable refresh, repository-access checks, and webhook delivery replace ad-hoc tokens, built on the existing managed connections and encrypted grants (#12843). When several people steer one agent, managed Git, gh, and GitHub tools resolve to the responsible person's credentials per accepted instruction — with durable continuation rules and no fallback to a teammate's access (#13005), and that identity projects into sandbox runners too (#12907). Around the core: browse repository access across organizations (#12998), select multiple source repositories per project (#13010), duplicate connections to the same GitHub account resolve cleanly (#13022), and sign-in state and connected-repository access are visible and simplified in the UI (#12993, #13047, #12893).
  • Announcements arrive in the app — A native announcement card renders a validated JSON feed with native components (the hero can be a static image or isolated HTML/CSS animation), so publishing or withdrawing a card needs no app release. Dismissals persist per account on the instance — a closed card stays closed across companies and browsers — and named staging feeds let authors test content before production. On by default against the hosted feed; the Upgrade Guide has the opt-out. (#13403)
  • Onboarding walks straight to a working agent — The connect step opens as a model-source question with provider sign-in built in — one continuous sequence on a single card, API key entry included, with the pasted login code kept on screen and answered at once (#12440, #12863, #12801, #12820, #12613, #13193). Your first task now opens as a chat with a chief of staff that waits for your answer instead of running off on its own, and chief-of-staff hiring is reliable (#13068, #13317). Creating later agents borrows the same connection controls in a simplified wizard with reorganized configuration pages (#13011), and saved model connections are reused during setup instead of asking you to sign in again (#13161).

Improvements

  • Apps and the connector catalog grew up — Apps leaves its experimental gate, connection setup is shorter, and managed Google access works on a clean self-hosted install with a safe default origin (#12728). Underneath: connection grants and delegated identities (#12341), managed external MCP connectors (#12346), secure remote MCP and PostHog setup (#12339), Composio and Gmail connectors (#12342), an expanded self-serve catalog with intent-based setup (#12344, #12347, #12345), refined Postman and Shopify flows (#12357), and consolidated connector management (#12684). Google Workspace setup was later repaired end to end: catalog and creation use the same availability rules, ownership choices survive capability changes, and Paperclip is the default Google authentication method with custom OAuth one link away (#13289, #12619, #12623). Agents can also request new service connections from native task feeds, with connection actions reviewed from the task (#13058, #13063).
  • Model and provider updates — Claude Fable 5.1 is selectable in the Claude adapter with both direct Anthropic and Bedrock inference-profile IDs (#12730); Codex gains GPT-6 Astra with its model-specific controls (#12851); unset Claude models resolve to Opus 5 everywhere, with the default visible in agent configuration (#13055). Grok joins the sandbox device-login panel with a private, company-scoped credential home, curated into remote subscription runs and refreshed credentials copied back to the host (#12469, #12618, #12696). Each Codex account gets its own home and path secret, and an agent can bind to a Codex login other than the company default (#12709, #13067).
  • The native Paperclip Runner now does the whole job — and self-hosted installs get the gate open by default — Last release's groundwork became a complete experimental execution engine behind the enableNativeRunner flag, which now defaults to on for self-hosted instances (cloud-managed instances keep it off) (#13068): native Codex execution and a Claude ACPX runtime plus a qualified OpenCode runtime (#12616, #12590, #12588, #12691), managed provider backends (#12699), a remote execution substrate with secure transport (#12638, #12639), administration and observability (#12641), and native turns projected into task chat (#12617). The control is one unified flag that gates every setup path (#12656, #12666). The open default only unlocks the gate: explicitly configured local Codex, OpenCode, and qualified ACPX agents can use the runner, onboarding stays on legacy adapters, nothing switches automatically, and turning enableNativeRunner off in experimental settings closes it again.
  • Controls for operators — A managed experimental flag, enableIsolatedWorkspacesByDefault, makes every project without its own policy use isolated per-task git worktrees, so a fleet default no longer means editing each project by hand (#13444). New standard-trust agents can hire other agents by default — low-trust agents keep the disabled default (#12814). Sentry monitoring splits into SENTRY_DSN_FRONTEND and SENTRY_DSN_BACKEND with the old SENTRY_DSN still working as a fallback (#12678). The experimental settings page sheds dead controls and groups developer tools (#12681), and PAPERCLIP_HIDDEN_SETTINGS is honored in the production switcher menu too (#12788).
  • The task surface, refreshed — A streamlined navigation foundation with refined task and workspace surfaces, consistent hover/popover/spacing behavior, and compact dashboard and Live-runs cards you can actually scan (#12746, #12747, #12748, #12854, #12793, #13269). Work products get rich cards and a run-artifact inventory on the task Artifacts tab (#12717), a viewer=full document deep link opens the maximized side pane straight from an external notification (#12812), the composer gains a Stop control with simplified task controls, status badges, and inline blocker removal (#13104, #13097), single-choice questions advance on selection (#13234), runner activity condenses into rolling per-group summaries shared across live and saved views (#13255, #13274, #13421), tasks created from a task are shown by project (#13241), long task chats stay responsive during streaming (#13229, #13228), and mobile gets real entity-picker sheets, full-width task trees, and spacing passes (#13343, #13250, #13304, #13122).
  • Task search that finds the task — Full and quick search unify around PostgreSQL term coverage with explicit relevance bands and conservative typo recovery, judged against a scored corpus. (#13335)
  • Try it without touching your data — A foreground-only test-drive CLI command boots an isolated instance with its own data directory and a provider-backed CEO, with reuse safeguards and restored credential inputs (#12894, #12898); server startup no longer opens a browser unless explicitly asked (#12435).
  • Sandbox runs got faster and sturdier — Warm Daytona workspaces persist across turns with the host workspace staying the durability boundary (#12904, #12901), the HTTP/2 sandbox bridge carries binary bodies and attachment routes (#12923), selected skills stage into remote Claude ACP runs (#13196), and a lost sandbox control channel fails the turn fast instead of hanging it (#13158).

... (truncated)

Commits
  • 827ba8a fix: cancel stalled sandbox startup without waiting for setup (#13352)
  • 663c44c fix: continue conversations after confirmed remote runner stop (#13254)
  • 60469a0 feat(agent-login): resume an active login session and permit concurrent login...
  • 0a422fd feat(runner): add remote execution substrate (#12638)
  • b3343db feat(connections): add self-serve intent runtime (#12345)
  • a20a494 feat: add Grok device login to the sandbox login panel (#12469)
  • b06034d Write mode-constrained inbound files directly to their target (#12320)
  • 0cedb45 build(deps-dev): bump typescript from 5.9.3 to 7.0.2 (#11880)
  • 445547c feat(duplex): run the Daytona sandbox callback bridge over Node HTTP/2 (#12120)
  • 63df7ad feat(login): use the login pseudo-terminal for Codex device login and de-Clau...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@paperclipai/plugin-sdk](https://github.com/paperclipai/paperclip/tree/HEAD/packages/plugins/sdk) from 2026.817.0 to 2026.916.1.
- [Release notes](https://github.com/paperclipai/paperclip/releases)
- [Changelog](https://github.com/paperclipai/paperclip/blob/master/doc/RELEASE-AUTOMATION-SETUP.md)
- [Commits](https://github.com/paperclipai/paperclip/commits/v2026.916.1/packages/plugins/sdk)

---
updated-dependencies:
- dependency-name: "@paperclipai/plugin-sdk"
  dependency-version: 2026.916.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants