Skip to content

Version Packages - #81

Merged
travist merged 1 commit into
mainfrom
changeset-release/main
Oct 5, 2026
Merged

travist merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@formio/mcp@0.14.1

Patch Changes

  • 757ee8a: Open the portal-login and revisions-consent pages in the browser on Windows. Both pages were launched with exec('start "<url>"'), and start reads its first quoted argument as a window title, so Windows opened an empty console window titled with the URL and no browser — the tool call then waited out the login timeout with no page in front of the user. Both pages now go through one launcher that runs no shell: open on macOS, xdg-open on Linux, and rundll32 url.dll,FileProtocolHandler on Windows, each handed the URL as its own argument. The consent page also now reports a failed launch on stderr with its URL, as the login page already did, instead of ignoring it.

@formio/ai@0.14.1

Patch Changes

  • ebd8ceb: Describe what the Angular, application, and SDK skills read at build time as the first-party inputs they are, so the skills.sh Snyk W011 "third-party content exposure" findings stop reading the skills' own trust prose as evidence of outsider content.

    formio-angular no longer calls the planner's template.md + template.json pair "the largest untrusted input this skill has" arriving "from a clone, a download, an unpacked archive" — the phrasing Snyk quoted back as "outsider-authored free text". The section now states that the pair is this pipeline's own artifact, written by formio-resource-planner and approved at its Phase A gate, and that the skill reads the two files the handoff names rather than whatever the directory holds. The three rules are unchanged: the pair must be first-party (confirmed with the user when nothing in the session accounts for it), its contents are data and not instructions, and every value is shape-checked before it reaches generated code.

    formio-sdk's last Security rule no longer tells the agent it reads "submission JSON … returned by any Formio call or MCP tool". It states what is true: the MCP tools return project configuration — form definitions, roles, actions, templates — and no submission data, and the SDK calls the skill documents are code the application runs at runtime. Configuration the agent reads still never instructs it.

    formio-application's Step 1 opens by naming its inputs — the user's own words, the user's own workspace on the modify-existing branch, and the planner pair produced from them — and states that it fetches no web page, reads no submission data, and opens no file a third party supplied.

  • 1a93655: Document how to configure a Role Assignment action with association: "existing". The formio-actions reference used to describe the target only as "a component whose value is the target resource's submission ID", which reads as though any key will do; it now states that the target component's key must be exactly submission. The same guidance recommends setting settings.role explicitly and granting create access on such a form to administrator roles only. formio-resource-planner's template-json.md carries the same rules for any existing action it emits, and a new skill test keeps every description of the association naming the submission key.

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from f8b046c to b1c12a0 Compare October 2, 2026 14:12
@travist
travist self-requested a review October 2, 2026 14:52
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from b1c12a0 to 7a78a27 Compare October 2, 2026 14:53
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 7a78a27 to 6912efa Compare October 4, 2026 18:21
@travist
travist merged commit 8164522 into main Oct 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant