Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
4096 commits
Select commit Hold shift + click to select a range
2f3c580
fix(den): gate OAuth refresh on session liveness and stop reporting i…
benjaminshafii Jul 24, 2026
7ae6950
Arc-style shell: floating panel cards, denser chrome, sidebar account…
benjaminshafii Jul 24, 2026
59136b1
feat(den-web): server-render the workspace favicon from the org squar…
benjaminshafii Jul 24, 2026
03d837e
chore(release): bump to 0.18.0
benjaminshafii Jul 24, 2026
9f7a504
chore(aur): update PKGBUILD for 0.18.0
release-bot Jul 24, 2026
68ce4e5
fix(installer): trust every OS certificate source on inspected networ…
benjaminshafii Jul 24, 2026
218a13c
fix(den): attribute our own MCP lifecycle deadline to OpenWork (#3088)
benjaminshafii Jul 24, 2026
12b0e88
feat(composer): render skills as /slug pills; default to empty state …
benjaminshafii Jul 24, 2026
39e734a
test(installer): prove OS trust-store pickup on real Windows (#3089)
benjaminshafii Jul 24, 2026
73893d2
feat: add guided organization install activation (#3084)
benjaminshafii Jul 24, 2026
8ea3d9b
fix(composer): align the new-task composer with the cards below it (#…
benjaminshafii Jul 25, 2026
b60c1f4
fix(nuke): wipe workspace and session state on fresh start (#3094)
benjaminshafii Jul 25, 2026
09dc7c0
chore(release): v0.18.1 (#3095)
benjaminshafii Jul 25, 2026
cb9ecdf
chore(aur): update PKGBUILD for 0.18.1
release-bot Jul 25, 2026
d0aac1e
feat(shell): fold the bottom status bar into the sidebar account menu…
benjaminshafii Jul 25, 2026
fcb2a62
chore(installer): report the real release version (#3098)
benjaminshafii Jul 25, 2026
dd6f3f0
refactor: collapse path, base-URL and workspace-store duplication int…
benjaminshafii Jul 25, 2026
087ef0e
fix(shell): keep live status inside the account menu, not on the coll…
benjaminshafii Jul 25, 2026
363ab0a
fix(den): bound config object version payloads
benjaminshafii Jul 25, 2026
d2b6199
fix(den): widen config object version payload columns
benjaminshafii Jul 25, 2026
b8546fd
fix(den): preserve admin capability arguments (#3102)
benjaminshafii Jul 25, 2026
c82f8bb
test(den): add config object payload boundary smoke (#3103)
benjaminshafii Jul 25, 2026
0c75029
feat(den-web): rework "Continue on your computer" install step (#3099)
benjaminshafii Jul 25, 2026
2fda607
fix(sidebar): align every row on shared glyph and label lanes (#3116)
benjaminshafii Jul 25, 2026
e61c527
docs: document team prompts and token usage (#3109)
benjaminshafii Jul 25, 2026
0bbe89d
docs: add capability concept tutorials (#3108)
benjaminshafii Jul 25, 2026
569008b
test(den-web): assert install-link error intent instead of stale copy…
benjaminshafii Jul 25, 2026
ea58461
fix(settings): wire extension readiness routing (#3111)
benjaminshafii Jul 25, 2026
9a40556
feat(den-web): preview desktop prompt cards (#3114)
benjaminshafii Jul 25, 2026
8f3e837
chore(installer): report the real release version (#3105)
benjaminshafii Jul 25, 2026
4746abb
Revert "feat(den-web): preview desktop prompt cards (#3114)"
benjaminshafii Jul 25, 2026
81c4b79
fix(den-web): describe the real macOS installer steps (#3121)
benjaminshafii Jul 25, 2026
60f31db
test(evals): refresh the installer release contract for DMG artifacts…
benjaminshafii Jul 25, 2026
34cbd65
fix(den): restore the external MCP tool-call budget on the live clien…
benjaminshafii Jul 25, 2026
d0ccf3a
test(evals): drop core flow reopen requirement (#3123)
benjaminshafii Jul 25, 2026
1345d51
feat(desktop): isolate dev profiles per worktree (#3124)
benjaminshafii Jul 25, 2026
2cbc4c7
docs: refresh create skill from chat flow (#3130)
benjaminshafii Jul 25, 2026
72fb04e
fix(desktop): route updater manifest through OS trust and guard bare …
benjaminshafii Jul 25, 2026
cb4c139
docs(enterprise): document outbound network access and guard it in CI…
benjaminshafii Jul 25, 2026
7148bda
docs(helm): expose the private-network MCP opt-out to operators (#3133)
benjaminshafii Jul 25, 2026
bf32618
docs(self-host): make the cloud catalog diagnostic actionable on-prem…
benjaminshafii Jul 25, 2026
5fc4a4b
docs(self-host): document the private-network (semi air-gapped) deplo…
benjaminshafii Jul 25, 2026
4e675e0
test(evals): pin the semi air-gapped Den deployment contract (#3136)
benjaminshafii Jul 25, 2026
743d7d8
docs(self-host): consolidate network, air-gap, and certificate guidan…
benjaminshafii Jul 25, 2026
a529b45
test(den): make Skill CRUD proof Daytona-ready (#3141)
reachjalil Jul 26, 2026
bc6b20d
fix(evals): start native MariaDB in root runtimes (#3142)
reachjalil Jul 26, 2026
9859662
fix(evals): resume authenticated native MariaDB (#3143)
reachjalil Jul 26, 2026
b92be76
fix(evals): resolve source exports in Den seed (#3145)
reachjalil Jul 26, 2026
9c8099c
fix(evals): allow isolated Den demo signup (#3146)
reachjalil Jul 26, 2026
f9c6192
fix(evals): clear stale Den Web build cache (#3147)
reachjalil Jul 26, 2026
6a1260d
fix(evals): trust Den proof loopback origins (#3148)
reachjalil Jul 26, 2026
85f149e
fix(policy): actually enforce org-managed models on the desktop (#3140)
benjaminshafii Jul 26, 2026
a3cf39b
feat(cloud): OpenWork Cloud alpha — a full instance in the browser, n…
benjaminshafii Jul 26, 2026
a0758de
fix(desktop): keep external fetches on Chromium network stack (#3149)
benjaminshafii Jul 26, 2026
776d079
chore: release v0.18.2
benjaminshafii Jul 26, 2026
2d5d7f4
fix(cloud): complete the web sign-in loop back into the instance (#3151)
benjaminshafii Jul 26, 2026
ba5a26a
fix(models): recover managed model empty state (#3150)
benjaminshafii Jul 26, 2026
cfec9f0
fix(den): answer CORS for the handoff exchange from Cloud instance or…
benjaminshafii Jul 26, 2026
2f73ebc
fix(release): stage server npm package (#3152)
benjaminshafii Jul 26, 2026
5e7e788
fix(den-web): let signed-in Cloud instances reach Den, bearer-only (#…
benjaminshafii Jul 26, 2026
1f3928a
chore(aur): update PKGBUILD for 0.18.2
release-bot Jul 26, 2026
b0f3d17
fix(cloud): require org choice after handoff (#3154)
benjaminshafii Jul 26, 2026
1a609e4
chore: bump version to 0.18.3
benjaminshafii Jul 26, 2026
0cfe388
chore(aur): update PKGBUILD for 0.18.3
release-bot Jul 26, 2026
e75aa18
fix(cloud): per-user instances and a safe worker state machine (#3156)
benjaminshafii Jul 26, 2026
b4a10e8
fix(cloud): ship the OpenCode plugins in the Cloud snapshot (#3157)
benjaminshafii Jul 26, 2026
dd6b1be
docs: clarify connectors, skills, and plugins (#3129)
benjaminshafii Jul 26, 2026
1f41a52
ignore: update download stats 2026-07-26
actions-user Jul 26, 2026
1333a38
feat(den-web): make cloud setup two steps — install the app, turn on …
benjaminshafii Jul 27, 2026
7567eae
fix(den): download desktop app directly (#3166)
reachjalil Jul 27, 2026
35c2d22
fix(den-web): align org chooser with desktop sign-in card (#3167)
benjaminshafii Jul 27, 2026
c23f487
fix(desktop): scope nuke to the profile that ran it; opt-in bootstrap…
benjaminshafii Jul 27, 2026
7dc9438
fix(sidebar): nest sessions under folders and add workspace avatars (…
benjaminshafii Jul 27, 2026
581a50a
chore(settings): remove the Customization tab (#3172)
benjaminshafii Jul 27, 2026
b5b3bc6
feat(den-web): rename LLM Providers to Bring your Own Keys and rebuil…
benjaminshafii Jul 27, 2026
129a446
feat(den-web): rebuild OpenWork Models page on shared den primitives …
benjaminshafii Jul 27, 2026
840c7ba
feat(den-web): rebuild onboarding around the desktop app and model ch…
benjaminshafii Jul 27, 2026
bfd9897
Add Den-activated enterprise desktop distribution (#3170)
reachjalil Jul 27, 2026
76565e9
chore(release): v0.18.4
benjaminshafii Jul 27, 2026
8782c0a
fix(desktop): stop pinning the updater test to a released version (#3…
benjaminshafii Jul 27, 2026
6c70f18
feat(den-web): rebuild OpenWork Models page on the Paper redesign (#3…
benjaminshafii Jul 27, 2026
a137da6
fix(release): unblock Daytona and AUR publishing (#3175)
benjaminshafii Jul 27, 2026
fe00265
chore(aur): update PKGBUILD for 0.18.4
release-bot Jul 27, 2026
ee4ec02
fix(connect): align OAuth windows with install UI (#3169)
reachjalil Jul 27, 2026
dc75c67
fix(desktop): reveal enterprise activation gate (#3179)
reachjalil Jul 27, 2026
4b93ea0
feat: add sign-in-required OpenWork Cloud installer (#3177)
reachjalil Jul 27, 2026
50a300a
chore(release): v0.18.5
benjaminshafii Jul 27, 2026
f50999f
ignore: update download stats 2026-07-27
actions-user Jul 27, 2026
e84ef30
feat(extensions): unify Extensions inventory and retire Connect tab (…
benjaminshafii Jul 27, 2026
f2ab33f
chore(aur): update PKGBUILD for 0.18.5
release-bot Jul 27, 2026
b4e16c1
chore: update models snapshot (#3183)
github-actions[bot] Jul 27, 2026
d7e295a
fix(desktop): keep Enterprise activation isolated (#3185)
reachjalil Jul 27, 2026
90983ea
fix(den-web): remove redundant cloud download action (#3186)
reachjalil Jul 27, 2026
eb5a9fb
chore(release): v0.18.6
benjaminshafii Jul 27, 2026
9ef5364
chore(aur): update PKGBUILD for 0.18.6
release-bot Jul 27, 2026
2e84099
fix(app): restore the Extensions typecheck (#3192)
benjaminshafii Jul 27, 2026
ede90f6
fix(composer): collapse pasted text only when it would scroll (#3193)
reachjalil Jul 27, 2026
a6080f8
fix(app): render markdown tables in the artifact editor (#3190)
benjaminshafii Jul 27, 2026
9d14c9b
chore: remove the openwork-orchestrator (#3181)
benjaminshafii Jul 27, 2026
173bab4
feat(extensions): name apps, connections, and MCPs consistently (#3196)
benjaminshafii Jul 27, 2026
dda3325
feat(diagnostics): add independent runtime MCP verification with deta…
reachjalil Jul 27, 2026
c0cd5ae
feat(den-gateway): serve the app and route each user to their own ins…
benjaminshafii Jul 27, 2026
0fcc716
fix(diagnostics): probe activated on-prem Den origins and correct eng…
reachjalil Jul 27, 2026
2fe88f8
chore(release): v0.18.7
reachjalil Jul 27, 2026
ae887a2
chore(aur): update PKGBUILD for 0.18.7
release-bot Jul 27, 2026
85fdf06
feat(den-gateway): one origin, gateway sign-in returns, and a publish…
benjaminshafii Jul 27, 2026
514d853
fix(desktop): load system CAs from OS trust stores; remove obsolete i…
benjaminshafii Jul 27, 2026
6b12dd0
fix(updater): keep staged updates installable and self-heal the insta…
benjaminshafii Jul 27, 2026
d1c395b
feat(diagnostics): capture MCP registration errors and cloud endpoint…
benjaminshafii Jul 27, 2026
0589602
fix(diagnostics): omit SNI servername for IP-literal cloud endpoints …
benjaminshafii Jul 27, 2026
965de30
fix(app): stabilize gateway bootstrap snapshot (#3205)
benjaminshafii Jul 27, 2026
e08e0a1
fix(gateway): send sign-in to den-web and approve the gateway return …
benjaminshafii Jul 27, 2026
d6bec90
fix(app): reflect the Den session after a web handoff instead of show…
benjaminshafii Jul 27, 2026
1aba9e3
feat(den-web): replace cloud tab with web launch (#3215)
benjaminshafii Jul 28, 2026
77c1b90
feat(desktop): repair incomplete TLS chains for org server (#3218)
benjaminshafii Jul 28, 2026
6c9b7b2
chore(release): v0.18.8
benjaminshafii Jul 28, 2026
9d6d027
fix(desktop): integrate Linux AppImages (#3217)
yomgui Jul 28, 2026
b51290f
fix(den-api): adopt an existing Daytona sandbox instead of wedging th…
benjaminshafii Jul 28, 2026
0e899c0
chore(aur): update PKGBUILD for 0.18.8
release-bot Jul 28, 2026
30ca723
fix(desktop): repair AppImage launcher silently after updates (#3220)
benjaminshafii Jul 28, 2026
2b7fdb5
fix(desktop): widen chain-repair budgets for slow networks (#3222)
benjaminshafii Jul 28, 2026
1d86565
chore(release): v0.18.9
benjaminshafii Jul 28, 2026
5fbc252
chore(aur): update PKGBUILD for 0.18.9
release-bot Jul 28, 2026
f312104
perf(extensions): prefetch the organization inventory, add a list vie…
benjaminshafii Jul 28, 2026
2a3ab01
fix(den-web): drop the member Available resources summary strip (#3223)
benjaminshafii Jul 28, 2026
2017315
feat(den-api): admin tool to grant and revoke the per-org Cloud capab…
benjaminshafii Jul 28, 2026
c3f6a6a
feat(den): manage Plugin Skills and Plugin lifecycle (#3144)
reachjalil Jul 28, 2026
5f8e6f8
fix(landing): route contact and feedback links (#3227)
OmarMcAdam Jul 28, 2026
6b46409
fix(connect): honor grants for admin desktop capabilities (#3159)
reachjalil Jul 28, 2026
2084368
ignore: update download stats 2026-07-28
actions-user Jul 28, 2026
afdf8a3
feat(den-api): checkpoint sandbox state and recycle stale sandboxes o…
benjaminshafii Jul 28, 2026
48629e1
fix(app): allow attachments in the new-task composer before the sessi…
benjaminshafii Jul 28, 2026
0aa8dfb
fix(gateway): proxy instance requests with the host token so host-sco…
benjaminshafii Jul 28, 2026
924b5e6
feat: cloud workspace overlay — status, version, and one-click update…
benjaminshafii Jul 28, 2026
9f9bf3d
fix(gateway): inject client bearer + host-token header, and send Den …
benjaminshafii Jul 28, 2026
1ad32e6
feat(den-api): log account deletion requests in Linear (#3235)
OmarMcAdam Jul 28, 2026
7162c73
feat(app): boot states take over the main area; kill the stale worksp…
benjaminshafii Jul 28, 2026
3b8c66e
fix(den-api): converge concurrent wake starts instead of flashing fai…
benjaminshafii Jul 28, 2026
ff24deb
feat(extensions): denser default list view for the inventory (#3240)
benjaminshafii Jul 28, 2026
11f9736
feat(app): replace OpenWork Models startup dialog with a quiet inline…
benjaminshafii Jul 28, 2026
beef8f0
feat(inference): add Claude Fable 5 to OpenWork models (#3241)
benjaminshafii Jul 28, 2026
fa35250
feat(den-web): align onboarding layout with the Paper design (#3245)
benjaminshafii Jul 28, 2026
fc498e1
revert(inference): remove Claude Fable 5 from OpenWork models (#3244)
benjaminshafii Jul 28, 2026
3d1a68c
fix(den-web): resume reaccepted organization invites (#3242)
reachjalil Jul 28, 2026
62d6cb1
feat(den): BYOK provider editor redesign — auto-name, Everyone access…
benjaminshafii Jul 28, 2026
33c3585
style(sidebar): tighten row spacing (#3248)
reachjalil Jul 28, 2026
e1643b2
fix(den): resolve already-accepted invites, make member removal stick…
benjaminshafii Jul 28, 2026
a0dcb63
style(sidebar): align search and footer edge (#3249)
reachjalil Jul 28, 2026
3f03f9e
feat(den-api): materialize cloud providers server-side (#3250)
benjaminshafii Jul 28, 2026
039c692
fix(chat): fold finished turns behind 'Worked for…' and keep tool agg…
benjaminshafii Jul 28, 2026
a2e66aa
feat(den-web): make the member dashboard a single download action (#3…
benjaminshafii Jul 28, 2026
bbc7fbf
feat(email): redesign organization invite with app design tokens and …
benjaminshafii Jul 28, 2026
43b3ff2
fix(den-api): make provider materialization atomic and verify it from…
benjaminshafii Jul 28, 2026
7e8c44c
feat: make cloud LLM providers engine-global so they actually reach o…
benjaminshafii Jul 28, 2026
17a91ae
chore: update models snapshot (#3256)
github-actions[bot] Jul 28, 2026
6441717
fix(den-api): tolerate sandboxes older than den-api (stop rolling bac…
benjaminshafii Jul 28, 2026
2e21cf1
fix(app): retry model access from composer hint (#3247)
reachjalil Jul 29, 2026
f1e1cb5
feat(extensions): connect, reconnect, and disconnect org connections …
benjaminshafii Jul 29, 2026
8e5e074
feat(evals): composition kernel — scenarios, surfaces, actors, hosts,…
benjaminshafii Jul 29, 2026
ff93acc
chore(release): v0.18.10
benjaminshafii Jul 29, 2026
9cc2545
chore(aur): update PKGBUILD for 0.18.10
release-bot Jul 29, 2026
1e98838
chore(agents): two-tier executors on gpt-5.6-sol-fast with delegation…
benjaminshafii Jul 29, 2026
72aa448
fix(app): stop a malformed workspace list from making the app unloada…
benjaminshafii Jul 29, 2026
f9991dd
perf(app): load composer skills/MCP/extensions instantly (local-first…
benjaminshafii Jul 29, 2026
07083ac
fix(app): render dark theme previews correctly (#3266)
reachjalil Jul 29, 2026
50513a4
fix(den): preserve model access policy on member rejoin (#3270)
reachjalil Jul 29, 2026
d186945
feat(evals): kube stage provider — kind + helm Den placement with pos…
benjaminshafii Jul 29, 2026
9d5f3fa
feat(evals): core reliability suite — invite + MCP unhappy paths, dua…
benjaminshafii Jul 29, 2026
10d379e
feat(evals): egress/TLS fault lab + diagnostics that name the fault (…
benjaminshafii Jul 29, 2026
ae92d2d
feat(evals): release lab — hermetic update feed + artifact host drivi…
benjaminshafii Jul 29, 2026
9644582
feat(evals): mock IdP lab — SSO misconfig, blocked users, invite prev…
benjaminshafii Jul 29, 2026
750dbbc
feat(evals): hostile-gateway MCP faults + product diagnosis findings …
benjaminshafii Jul 29, 2026
e20686f
fix(den): harden organization re-invite lifecycles (#3272)
reachjalil Jul 29, 2026
2672ff3
fix(app): skip client cloud provider sync in gateway (#3275)
benjaminshafii Jul 29, 2026
e1ce2d9
build(app): move Tailwind configuration to CSS (#3269)
reachjalil Jul 29, 2026
c953733
fix(app): exempt web opencode streams from timeout (#3279)
benjaminshafii Jul 29, 2026
25db339
test(evals): add dashboard UI acceptance flows (#3280)
reachjalil Jul 29, 2026
0f8acd4
fix(den): harden team lifecycle cleanup (#3276)
reachjalil Jul 29, 2026
96dada3
fix(den): preserve role invitation history (#3277)
reachjalil Jul 29, 2026
0561ecf
fix(den): clean legacy SCIM state on rotation (#3278)
reachjalil Jul 29, 2026
40c7acf
fix(app): stop credential changes from tearing down the agent event s…
benjaminshafii Jul 29, 2026
b7a3292
fix(den): migrate legacy SSO providers on update (#3281)
reachjalil Jul 29, 2026
49b66a9
fix(app): stop ref-count churn from aborting the agent event stream (…
benjaminshafii Jul 29, 2026
74ffa28
Fix Den evaluator organization chooser handoff (#3293)
reachjalil Jul 29, 2026
f74ee84
ignore: update download stats 2026-07-29
actions-user Jul 29, 2026
e6eb054
Wait for Flat Plugin evaluator navigation (#3295)
reachjalil Jul 29, 2026
97d1667
fix(den): harden bootstrap claim lifecycle (#3294)
reachjalil Jul 29, 2026
e761c74
Make Den evaluator organization selection deterministic (#3297)
reachjalil Jul 29, 2026
f203e05
fix(den): restrict mcp connector deletion (#3296)
OmarMcAdam Jul 29, 2026
f4c6f21
Allow cold compilation in Flat Plugin evaluator (#3299)
reachjalil Jul 29, 2026
1fd5569
fix(den-api): stop provider re-materialization from aborting live age…
benjaminshafii Jul 29, 2026
9b9bb1e
fix(den): serialize invitation state transitions (#3292)
reachjalil Jul 29, 2026
00617cd
feat(evals): composable @openwork packages + flat vitest spec lane (c…
benjaminshafii Jul 29, 2026
0ea1186
test(evals): seed flat plugin proof data (#3305)
reachjalil Jul 29, 2026
63faae4
fix(app): type Sonner custom properties (#3309)
benjaminshafii Jul 29, 2026
723c9db
fix(server): a no-op provider patch must not reload the engine (#3307)
benjaminshafii Jul 29, 2026
7baea6a
fix(app): advance the session-groups event cursor instead of refetchi…
benjaminshafii Jul 29, 2026
0f644d7
fix(evals): harden clean Daytona proof setup (#3306)
reachjalil Jul 29, 2026
64786c4
fix(app): wait for signed-in Den startup before Run Task (#3300)
reachjalil Jul 29, 2026
3ffd875
test(evals): add sidebar and panel snack flows (#3314)
reachjalil Jul 29, 2026
0de0798
fix(evals): standalone evals pnpm workspace + CodeQL fixes + probe-tl…
benjaminshafii Jul 29, 2026
90e7941
fix(evals): generate the egress lab root CA with -extfile (openssl 1.…
benjaminshafii Jul 29, 2026
0ff02a8
feat(release): make the Daytona snapshot pin follow releases, and rej…
benjaminshafii Jul 29, 2026
ed16748
chore: bump version to 0.18.11 (#3319)
benjaminshafii Jul 29, 2026
6dae98d
chore(aur): update PKGBUILD for 0.18.11
release-bot Jul 29, 2026
32ba471
fix(release): redeploy den-api after updating the snapshot pin so it …
benjaminshafii Jul 29, 2026
9820fe3
fix(server): deliver managed provider credentials to the engine auth …
benjaminshafii Jul 30, 2026
1119afb
chore: bump version to 0.18.12 (#3334)
benjaminshafii Jul 30, 2026
2d42753
chore(aur): update PKGBUILD for 0.18.12
release-bot Jul 30, 2026
986e618
fix(den-api): key the materialization cache per instance so a recycle…
benjaminshafii Jul 30, 2026
9ffb0ef
fix(app): support super-admin organizations on desktop (#3336)
reachjalil Jul 30, 2026
520eba3
fix(app): move attachment actions into a menu (#3337)
reachjalil Jul 30, 2026
e94befe
fix(app): refresh artifact panel when agent modifies the open file (#…
PriyeshPandey2000 Jul 30, 2026
17571c3
fix(app): support custom organization roles on desktop (#3341)
reachjalil Jul 30, 2026
f0b9ec6
fix(app): show loading feedback while chat submits (#3335)
reachjalil Jul 30, 2026
abeff6f
feat(evals): three proof primitives (screenshot / validate / photoRol…
benjaminshafii Jul 30, 2026
a67ba4d
fix(den-api): checkpoint the engine session database so recycles keep…
benjaminshafii Jul 30, 2026
65134ae
Open Extensions as a first-class main-sidebar page (#3287)
reachjalil Jul 30, 2026
daeb3a8
feat(den): use flat colors for catalog cards (#3286)
reachjalil Jul 30, 2026
d6c4b20
test(evals): add conversation activity completion flow (#3343)
reachjalil Jul 30, 2026
09143f5
fix(evals): app readiness as interactive UI, shared predicate, den bo…
benjaminshafii Jul 30, 2026
cabcb3b
Add a useful right-panel action chooser (#3330)
reachjalil Jul 30, 2026
b5fb89e
fix(release): respect protected dev workflow (#3195)
OmarMcAdam Jul 30, 2026
7908ad1
fix(den): restrict mcp connector updates (#3302)
OmarMcAdam Jul 30, 2026
6041f57
feat: Rename dashboard Stripe terminology to Billing (#3284)
reachjalil Jul 30, 2026
9ea0f01
Add platform-number shortcuts for visible chat sessions (#3331)
reachjalil Jul 30, 2026
34946eb
fix(den-api): detect instances too old for the provider route instead…
benjaminshafii Jul 30, 2026
8b0c86f
feat: Mark Sources as Alpha (#3328)
reachjalil Jul 30, 2026
cb210eb
fix(den): harden email sign-in resolution (#3298)
OmarMcAdam Jul 30, 2026
eb0dbef
fix(app): open browser without a session (#3346)
reachjalil Jul 30, 2026
a619ded
fix stuck session shortcut modifier state (#3347)
reachjalil Jul 30, 2026
7453d64
Show more of long chat titles on hover and focus (#3329)
reachjalil Jul 30, 2026
55fcd32
ignore: update download stats 2026-07-30
actions-user Jul 30, 2026
f673d74
build(deps-dev): bump vite from 6.4.1 to 6.4.3 (#3356)
dependabot[bot] Jul 30, 2026
319e071
build(deps-dev): bump postcss from 8.4.38 to 8.5.18 (#3357)
dependabot[bot] Jul 30, 2026
7e95269
build(deps): bump @better-auth/scim from 1.6.11 to 1.6.25 (#3358)
dependabot[bot] Jul 30, 2026
239bb02
fix(den): disable BotID enforcement by default (#3363)
OmarMcAdam Jul 30, 2026
2c558bc
ci: add dependabot cooldown (#3364)
OmarMcAdam Jul 30, 2026
c639f8b
build(deps): bump tailwind-merge from 3.5.0 to 3.6.0 (#3369)
dependabot[bot] Jul 31, 2026
062d663
build(deps): bump minimatch from 10.1.1 to 10.2.5 (#3368)
dependabot[bot] Jul 31, 2026
64c3c7e
build(deps-dev): bump tsx from 4.21.0 to 4.23.1 (#3367)
dependabot[bot] Jul 31, 2026
1d7fa02
build(deps): bump @codemirror/lang-markdown from 6.5.0 to 6.5.1 (#3366)
dependabot[bot] Jul 31, 2026
0ab3e9a
build(deps): bump next from 16.2.1 to 16.2.11 (#3362)
dependabot[bot] Jul 31, 2026
d8b869e
build(deps): bump react-dom and @types/react-dom (#3365)
dependabot[bot] Jul 31, 2026
6e70e1d
feat(gateway): replace the stalled boot bar with a checkpoint ladder …
benjaminshafii Jul 31, 2026
503d1ec
feat(connections): show real provider logos across the connect flow (…
benjaminshafii Jul 31, 2026
736ed47
Revert "fix(app): wait for signed-in Den startup before Run Task (#33…
benjaminshafii Jul 31, 2026
87be560
fix(ci): stop compiling better-sqlite3 from source on Node 24 (#3378)
benjaminshafii Jul 31, 2026
915c43d
feat(evals): core journeys green on real infra, environment healing b…
benjaminshafii Jul 31, 2026
0e84c10
feat(evals): make surface placement explicit, and own browser disposa…
benjaminshafii Jul 31, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
38 changes: 38 additions & 0 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# Full Electron + Den dev environment for Daytona sandboxes.
#
# Clones the repo from GitHub, installs deps, and provides
# Xvfb + noVNC so you can see/steer the real Electron app
# from your browser.

FROM node:20-bookworm

# System deps for Electron / Chromium + virtual display + utils
RUN apt-get update && apt-get install -y --no-install-recommends \
git unzip dbus dbus-x11 \
libgtk-3-0 libnotify-dev libnss3 libxss1 libasound2 \
libxtst6 libatk-bridge2.0-0 libdrm2 libgbm1 libxrandr2 \
libxcomposite1 libxdamage1 libxfixes3 libcups2 \
libpango-1.0-0 libcairo2 \
xvfb x11vnc novnc websockify fluxbox xterm \
default-mysql-client \
&& rm -rf /var/lib/apt/lists/*

# pnpm + bun
RUN corepack enable && corepack prepare pnpm@latest --activate
RUN npm install -g bun

# noVNC index
RUN ln -sf /usr/share/novnc/vnc.html /usr/share/novnc/index.html

ENV DISPLAY=:99
ENV ELECTRON_DISABLE_SANDBOX=1
ENV PNPM_HOME=/root/.local/share/pnpm
ENV PATH=$PNPM_HOME:$PATH

# Clone and install
ARG REPO_URL=https://github.com/different-ai/openwork.git
ARG BRANCH=dev
WORKDIR /workspace
RUN git clone --depth 1 --branch $BRANCH $REPO_URL . && pnpm install --frozen-lockfile || pnpm install

EXPOSE 3005 5173 6080 8788 9825
36 changes: 36 additions & 0 deletions .devcontainer/Dockerfile.daytona-server
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# Daytona image for the OpenWork Den server stack.
#
# This intentionally does not run Docker inside Daytona. The sandbox runs the
# same services as packaging/docker/docker-compose.den-dev.yml directly:
# MySQL, Den API, Den Web, and the worker proxy.
FROM daytonaio/sandbox:0.6.0

USER root

RUN apt-get update \
&& DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
ca-certificates \
curl \
default-mysql-client \
default-mysql-server \
git \
procps \
sudo \
&& /usr/local/share/nvm/current/bin/npm install -g pnpm@10.27.0 bun \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/* /root/.cache /root/.npm /tmp/*

WORKDIR /workspace

RUN git clone --depth 1 --branch dev https://github.com/different-ai/openwork.git . \
&& mkdir -p /workspace/.openwork-daytona \
&& sha256sum /workspace/pnpm-lock.yaml | cut -d ' ' -f 1 > /workspace/.openwork-daytona/pnpm-lock.sha256 \
&& git gc --prune=now \
&& rm -rf /home/daytona/.cache /home/daytona/.npm /home/daytona/.local/share/pnpm/store \
/workspace/node_modules

RUN chown -R daytona:daytona /workspace \
&& printf 'daytona ALL=(ALL) NOPASSWD:ALL\n' >/etc/sudoers.d/daytona-openwork \
&& chmod 0440 /etc/sudoers.d/daytona-openwork

USER daytona
29 changes: 29 additions & 0 deletions .devcontainer/Dockerfile.daytona-vnc
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Daytona VNC/Computer Use image with OpenWork preinstalled.
#
# Use this for Electron/noVNC tests instead of the generic devcontainer image.
# The base image already contains the desktop stack Daytona expects:
# Xvfb, XFCE, x11vnc, noVNC, websockify, and dbus-x11.
FROM daytonaio/sandbox:0.6.0

USER root

RUN apt-get update \
&& apt-get install -y --no-install-recommends ffmpeg \
&& rm -rf /var/lib/apt/lists/*

RUN /usr/local/share/nvm/current/bin/npm install -g pnpm@10.27.0 bun

WORKDIR /workspace

RUN git clone --depth 1 --branch dev https://github.com/different-ai/openwork.git . \
&& mkdir -p /workspace/.openwork-daytona \
&& sha256sum /workspace/pnpm-lock.yaml | cut -d ' ' -f 1 > /workspace/.openwork-daytona/pnpm-lock.sha256 \
&& /usr/local/share/nvm/current/bin/npm cache clean --force \
&& git gc --prune=now \
&& rm -rf /root/.cache /root/.npm \
/home/daytona/.cache /home/daytona/.npm /home/daytona/.local/share/pnpm/store \
/workspace/node_modules /tmp/*

RUN chown -R daytona:daytona /workspace

USER daytona
159 changes: 159 additions & 0 deletions .devcontainer/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,159 @@
# Daytona / Dev Container Setup

Full-stack dev environment that runs the **real Electron app** + Den stack in a cloud sandbox. You see and steer the desktop app through your browser via noVNC.

## What's included

| Service | Port | Description |
|---------|------|-------------|
| **Desktop App (noVNC)** | 6080 | The real Electron app rendered in a virtual display, accessible in your browser |
| **Den Web** | 3005 | Admin dashboard for managing orgs, restrictions, providers |
| **Den API** | 8788 | Control plane API |
| **CDP Debug** | 9825 | Chrome DevTools Protocol — for app and browser automation |
| **Vite HMR** | 5173 | Hot module replacement for the React UI |
| **MySQL** | 3306 | Database (internal) |

## Quick start with Daytona Electron/noVNC

```bash
bash .devcontainer/create-daytona-openwork-snapshot.sh # one-time / refresh when deps change
bash .devcontainer/test-on-daytona.sh [branch-or-commit]
```

The test script creates a sandbox from the reusable `openwork-eval-vnc` snapshot
when present, checks out the target ref, skips `pnpm install` if the lockfile is
unchanged, starts XFCE/noVNC, Vite, and Electron, then prints the noVNC and CDP
URLs. If the snapshot is missing, it fails fast and tells you to create it. The
snapshot intentionally does not bake `node_modules`; installs use the reusable
`openwork-eval-pnpm-store` volume so the image stays under Daytona's 20 GB limit.

For provider evals, create/populate the reusable Daytona secrets volume once:

```bash
bash .devcontainer/setup-daytona-secrets-volume.sh .newtoken
bash .devcontainer/setup-daytona-secrets-volume.sh .anthropic anthropic.env
```

Future Daytona test sandboxes mount `openwork-eval-secrets:/daytona-secrets`
and source every `/daytona-secrets/*.env` file automatically before Electron
starts. Use this volume for provider keys and other eval-only secrets; never
commit those files into the repo.

For downloadable eval artifacts or optional video recording, use:

```bash
bash .devcontainer/test-on-daytona.sh [branch-or-commit] --artifacts-volume
bash .devcontainer/test-on-daytona.sh [branch-or-commit] --record-video
```

The artifacts flow mounts `openwork-eval-artifacts:/daytona-artifacts`, starts a
static download server on port 8090, and prints a Daytona preview URL. Recording
writes mp4 files to `/daytona-artifacts/recordings` and prints the direct video
URL. Screenshots write png files to `/daytona-artifacts/screenshots` for quick
AI/human validation checkpoints. Stop recording with
`.devcontainer/stop-daytona-recording.sh` so ffmpeg finalizes the file cleanly.

Do not use the generic `daytona create https://github.com/different-ai/openwork`
flow for Electron/noVNC tests. The default resource size is too small and the
generic image path does not guarantee the desktop stack we need.

## Quick start with Daytona server

```bash
bash .devcontainer/create-daytona-openwork-server-snapshot.sh # one-time / refresh when deps change
bash .devcontainer/test-server-on-daytona.sh [branch-or-commit]
```

The server helper creates a separate public Daytona sandbox for the Den stack:
MySQL, Den API, Den Web, and the worker proxy. It prints public preview URLs and
the exact Electron command to point a desktop sandbox at that server:

```bash
bash .devcontainer/test-on-daytona.sh [branch-or-commit] \
--den-base-url https://3005-...daytonaproxy... \
--den-api-base-url https://8788-...daytonaproxy...
```

This keeps the architecture simple: the server sandbox owns cloud auth, orgs,
policies, workers, and persistence; the Electron sandbox stays a real desktop
client and talks to the server through public Daytona preview URLs.

## How it works

1. `.devcontainer/Dockerfile.daytona-vnc` starts from `daytonaio/sandbox:0.6.0`,
which includes Daytona's expected desktop packages: Xvfb, XFCE, x11vnc,
noVNC, websockify, and dbus-x11.
2. `.devcontainer/create-daytona-openwork-snapshot.sh` bakes that image into
`openwork-eval-vnc` without `node_modules`.
3. `/opt/openwork-daytona/start-daytona-vnc.sh` starts Xvfb, XFCE, x11vnc, and
noVNC on display `:99`.
4. `test-on-daytona.sh` installs dependencies through the reusable
`openwork-eval-pnpm-store` volume when `node_modules` is missing or the
lockfile changed.
5. Vite serves the React UI on port 5173.
6. `/opt/openwork-daytona/start-daytona-electron.sh` sources optional secrets,
applies Daytona-safe Chromium flags, and starts Electron on display `:99`.
7. **CDP on port 9825** enables Chrome MCP and browser-tool automation.
8. Optional artifact capture mounts `/daytona-artifacts`, serves it on port 8090,
records display `:99` with ffmpeg when `--record-video` is passed, and can
capture screenshot checkpoints with `.devcontainer/capture-daytona-screenshot.sh`.

## Validation Evidence

Use three layers of evidence for Daytona UI work:

- **CDP assertions:** use browser tools against port 9825 to inspect text, URL,
state, and accessibility snapshots. This is the primary AI validation path.
- **Screenshots:** run `daytona exec "$SANDBOX" -- 'bash .devcontainer/capture-daytona-screenshot.sh'` after important states. These png files live in `/daytona-artifacts/screenshots`.
- **Recordings:** start with `--record-video --recording-name <name>` for flows
that need PR evidence. These mp4 files live in `/daytona-artifacts/recordings`.

Recordings prove the flow to humans. CDP assertions and screenshots give the AI
fast checkpoints to decide whether behavior is correct before reporting success.

## AI Skills

The Daytona toolbox is exposed to opencode through focused skills:

- `daytona-dev`: overview of the Daytona setup and when to use each piece.
- `daytona-cloud-server`: Den Web/API, worker proxy, marketplace, cloud auth, and org policy flows.
- `daytona-secrets-volume`: add and verify provider keys or eval-only secrets in `/daytona-secrets`.
- `daytona-electron-test`: run and drive the real Electron app through CDP/noVNC.
- `daytona-recording-artifacts`: screenshots, recordings, before/after videos, and PR evidence.
- `run-evals`: orchestrates evals and pulls in the relevant Daytona skill based on the flow.

## Testing the customization system

1. Open **Den Web** (port 3005) in a separate tab
2. Sign up → create org → Org Settings → UI Customization
3. Set overrides → Save
4. In the **Electron app** (noVNC on port 6080):
- Cloud → developer mode → base URL `http://localhost:3005`
- Sign in → Settings → see the desktop policy banner

## Architecture

```
Your Browser
├── :6080 noVNC ──▶ x11vnc ──▶ XFCE/Xvfb ──▶ Electron App
│ │
│ ├── CDP :9825 (automatable)
│ └── Vite HMR :5173
├── :3005 Den Web (Next.js)
└── :8788 Den API (Hono) ──▶ MySQL :3306
```

With a separate server sandbox, the Electron box uses Daytona preview URLs for
Den Web/API instead of `localhost`, while the server sandbox still keeps its
internal service graph local.

## Automation

The Electron app exposes CDP on port 9825. You can:

- Connect Playwright: `const browser = await chromium.connectOverCDP('ws://localhost:9825')`
- Connect Chrome MCP for AI agent testing
- Take screenshots, run UI tests, etc.
63 changes: 63 additions & 0 deletions .devcontainer/capture-daytona-screenshot.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
#!/usr/bin/env bash
set -euo pipefail

# Capture a single Daytona Electron display frame as a PNG artifact. Screenshots
# are for quick AI/human validation; videos are still the durable PR evidence.

OUTPUT="/daytona-artifacts/screenshots/daytona-screenshot-$(date +%Y%m%d-%H%M%S).png"
SIZE="1920x1080"

while [ "$#" -gt 0 ]; do
case "$1" in
--output)
shift
OUTPUT="${1:?missing output path}"
;;
--size)
shift
SIZE="${1:?missing screenshot size}"
;;
--help|-h)
printf '%s\n' \
"Usage: capture-daytona-screenshot.sh [--output PATH] [--size WxH]" \
"" \
"Captures DISPLAY, defaulting to :99, and writes a PNG file."
exit 0
;;
--*)
echo "Unknown option: $1" >&2
exit 1
;;
*)
echo "Unexpected argument: $1" >&2
exit 1
;;
esac
shift
done

if ! command -v ffmpeg >/dev/null 2>&1; then
echo "ERROR: ffmpeg is required for Daytona screenshots." >&2
exit 1
fi

if [[ ! "$SIZE" =~ ^[0-9]+x[0-9]+$ ]]; then
echo "ERROR: screenshot size must use WxH format, for example 1920x1080" >&2
exit 1
fi

FINAL_OUTPUT="$OUTPUT"
CAPTURE_OUTPUT="$OUTPUT"
if [[ "$OUTPUT" = /daytona-artifacts/* ]]; then
CAPTURE_OUTPUT="/tmp/daytona-screenshot-$(basename "$OUTPUT")"
fi

mkdir -p "$(dirname "$CAPTURE_OUTPUT")"
ffmpeg -y -f x11grab -video_size "$SIZE" -i "${DISPLAY:-:99}" -frames:v 1 "$CAPTURE_OUTPUT" >/tmp/daytona-screenshot.log 2>&1

if [ "$CAPTURE_OUTPUT" != "$FINAL_OUTPUT" ]; then
mkdir -p "$(dirname "$FINAL_OUTPUT")"
cp "$CAPTURE_OUTPUT" "$FINAL_OUTPUT"
fi

echo "Screenshot saved: $FINAL_OUTPUT"
34 changes: 34 additions & 0 deletions .devcontainer/create-daytona-openwork-server-snapshot.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
#!/usr/bin/env bash
set -euo pipefail

# Build/refresh the reusable Daytona snapshot used by Den server sandboxes.

ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
SNAPSHOT_NAME="${DAYTONA_SERVER_SNAPSHOT:-openwork-server}"
REGION="${DAYTONA_TARGET:-us}"

snapshot_id() {
daytona snapshot list -f json | node -e 'const name = process.argv[1]; let input = ""; process.stdin.on("data", (chunk) => input += chunk); process.stdin.on("end", () => { const snapshot = JSON.parse(input).find((item) => item.name === name); if (snapshot) process.stdout.write(snapshot.id || snapshot.name); });' "$1"
}

existing_snapshot_id="$(snapshot_id "$SNAPSHOT_NAME")"
if [ -n "$existing_snapshot_id" ]; then
echo "==> Deleting existing snapshot: $SNAPSHOT_NAME"
daytona snapshot delete "$existing_snapshot_id" >/dev/null <<< "y"
for _ in $(seq 1 60); do
if [ -z "$(snapshot_id "$SNAPSHOT_NAME")" ]; then
break
fi
sleep 5
done
fi

echo "==> Creating Daytona server snapshot: $SNAPSHOT_NAME"
daytona snapshot create "$SNAPSHOT_NAME" \
--dockerfile "$ROOT_DIR/.devcontainer/Dockerfile.daytona-server" \
--cpu 4 \
--memory 8 \
--disk 10 \
--region "$REGION"

echo "Snapshot ready: $SNAPSHOT_NAME"
33 changes: 33 additions & 0 deletions .devcontainer/create-daytona-openwork-snapshot.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
#!/usr/bin/env bash
set -euo pipefail

# Build/refresh the reusable Daytona VNC snapshot used by eval sandboxes from
# the prebuilt GHCR image. The image is built by GitHub Actions on dev pushes.

SNAPSHOT_NAME="${DAYTONA_EVAL_SNAPSHOT:-openwork-eval-vnc}"
IMAGE="${DAYTONA_EVAL_IMAGE:-ghcr.io/different-ai/openwork-eval-vnc:dev}"
REGION="${DAYTONA_TARGET:-us}"

existing_snapshot_id="$(daytona snapshot list -f json | node -e 'const name = process.argv[1]; let input = ""; process.stdin.on("data", (chunk) => input += chunk); process.stdin.on("end", () => { const snapshot = JSON.parse(input).find((item) => item.name === name); if (snapshot) process.stdout.write(snapshot.id || snapshot.name); });' "$SNAPSHOT_NAME")"

if [ -n "$existing_snapshot_id" ]; then
echo "==> Deleting existing snapshot: $SNAPSHOT_NAME"
daytona snapshot delete "$existing_snapshot_id" >/dev/null <<< "y"
for _ in $(seq 1 60); do
if ! daytona snapshot list -f json | node -e 'const name = process.argv[1]; let input = ""; process.stdin.on("data", (chunk) => input += chunk); process.stdin.on("end", () => { const snapshot = JSON.parse(input).find((item) => item.name === name); process.exit(snapshot ? 1 : 0); });' "$SNAPSHOT_NAME"; then
sleep 5
else
break
fi
done
fi

echo "==> Creating Daytona eval snapshot: $SNAPSHOT_NAME"
daytona snapshot create "$SNAPSHOT_NAME" \
--image "$IMAGE" \
--cpu 4 \
--memory 8 \
--disk 10 \
--region "$REGION"

echo "Snapshot ready: $SNAPSHOT_NAME"
Loading