MERGE COMMIT REQUIRED: repair release/13.6 ancestry (DO NOT SQUASH OR REBASE) - #1697
David Pine (IEvangelist) merged 32 commits into
Conversation
* Keep docs versions current and default to TypeScript Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address TypeScript-first review feedback Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: aspire-repo-bot[bot] <aspire-repo-bot[bot]@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: aspire-repo-bot[bot] <aspire-repo-bot[bot]@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: aspire-repo-bot[bot] <aspire-repo-bot[bot]@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: aspire-repo-bot[bot] <aspire-repo-bot[bot]@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: aspire-repo-bot[bot] <aspire-repo-bot[bot]@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Fix: merge duplicate C#/.NET sidebar sections under Frameworks & runtimes * Clean:revert unrelated icon safelist regeneration * fix: match sidebar label to page title for .NET get-started item
* Claude's accessibility fixes. * Addressed list margins feedback from @Copilot.
* chore: Update integration data and GitHub stats (9/9/26) Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: keep integration documentation mappings synchronized Remove the stale Bun mapping, reconcile catalog-managed mappings during updates, and stage documentation-map changes in automated PRs. Validate structured data without Astro-generated asset side effects. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: aspire-repo-bot[bot] <aspire-repo-bot[bot]@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: David Pine <david.pine@microsoft.com>
* docs: restore Floci integration documentation Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs: address Floci review feedback Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: aspire-repo-bot[bot] <aspire-repo-bot[bot]@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* feat: improve search and agent discoverability Restore page-specific descriptions, publish useful homepage Markdown, strengthen observability guidance, and defer inactive AppHost examples. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: keep mobile homepage within layout budget Tighten spacing in the expanded observability section so the production mobile viewport remains within the existing compactness gate. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: align agent docs and search indexing Document authenticated standalone MCP with an explicit API key and keep deferred AppHost examples out of the homepage Pagefind index. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.17.0 to 1.18.0 Bumps OpenTelemetry.Extensions.Hosting from 1.17.0 to 1.18.0 Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.17.0 to 1.18.0 Bumps OpenTelemetry.Instrumentation.Http from 1.17.0 to 1.18.0 Bumps OpenTelemetry.Instrumentation.Runtime from 1.17.0 to 1.18.0 --- updated-dependencies: - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-selected - dependency-name: OpenTelemetry.Extensions.Hosting dependency-version: 1.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-selected - dependency-name: OpenTelemetry.Instrumentation.AspNetCore dependency-version: 1.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-selected - dependency-name: OpenTelemetry.Instrumentation.Http dependency-version: 1.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-selected - dependency-name: OpenTelemetry.Instrumentation.Runtime dependency-version: 1.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-selected ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…updates (#1601) Bumps the github-actions group with 2 updates in the / directory: [github/gh-aw-actions/setup](https://github.com/github/gh-aw-actions) and [github/gh-aw-actions/setup-cli](https://github.com/github/gh-aw-actions). Updates `github/gh-aw-actions/setup` from 0.87.1 to 0.88.0 - [Release notes](https://github.com/github/gh-aw-actions/releases) - [Changelog](https://github.com/github/gh-aw-actions/blob/main/CHANGELOG.md) - [Commits](github/gh-aw-actions@423b3dc...afc709f) Updates `github/gh-aw-actions/setup-cli` from 0.87.1 to 0.88.0 - [Release notes](https://github.com/github/gh-aw-actions/releases) - [Changelog](https://github.com/github/gh-aw-actions/blob/main/CHANGELOG.md) - [Commits](github/gh-aw-actions@423b3dc...afc709f) --- updated-dependencies: - dependency-name: github/gh-aw-actions/setup dependency-version: 0.87.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/gh-aw-actions/setup-cli dependency-version: 0.87.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Fix right TOC width at browser zoom levels Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Hide right TOC when mobile TOC is visible Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…AIFoundry references (#1163) * docs: clarify Foundry migration guidance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs: update Foundry package versions Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: b8ebe88c-337e-4d4a-aa80-e14c2c76289b --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Maddy Montaquila <maddy@MadBook-Pro-20.local> Copilot-Session: b8ebe88c-337e-4d4a-aa80-e14c2c76289b
…ck annotation references (#1158) * Update deployment docs to pipeline-step API Refresh custom deployment examples for pipeline steps and clarify legacy callback references in deployment, diagnostics, and release notes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5b0c81a3-d822-462e-8cf5-8eb6debfe968 * Apply suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Restore historical What's new content Keep release-version articles unchanged while retaining the current pipeline API updates elsewhere. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address deployment docs review feedback Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: b156fe61-0b1c-460c-9735-1eaeaa356b0a * Align Aspire 9.4 deployment example with pipelines Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: b156fe61-0b1c-460c-9735-1eaeaa356b0a --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: David Pine <david.pine@microsoft.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Maddy Montaquila <maddy@MadBook-Pro-20.local> Copilot-Session: 5b0c81a3-d822-462e-8cf5-8eb6debfe968 Copilot-Session: b156fe61-0b1c-460c-9735-1eaeaa356b0a
* Add live-status header icon, SSE backend, redesigned videos page
- Adds a strobing live-status indicator in the site header (left of the
cookie-preferences button) wired to a new /api/live SSE endpoint.
- Adds a custom floating PiP player that follows visitors across the
site while live and returns them to the videos page on close.
- Replaces the legacy curated /community/videos/ page with a focused
YouTube + Twitch tabbed page whose embed lights up when live.
- Adds an in-StaticHost background-worker stack:
* Twitch EventSub stream.online/offline subscription + reconcile,
* YouTube WebSub subscribe/renew + confirming poll fallback,
* a debounced LiveStatusBroadcaster with sticky primary-source
mesh logic and Channel<T> SSE fan-out.
- Surfaces the new endpoints + Scalar API reference (with a custom
Aspire-brand theme) on the Aspire dashboard for local dev.
- Includes a worktree cleanup helper script and PR_BODY.md.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add tests for live-status feature
- StaticHost.Tests xUnit project: TwitchWebhookHandler (HMAC-SHA256
round-trip + tamper detection), YouTubeWebhookHandler (HMAC-SHA1 +
Atom video-id extraction), LiveStatusBroadcaster (sticky-primary
mesh, coalesce window via FakeTimeProvider, subscribe/unsubscribe).
- vitest spec for live-status.ts public API.
- Playwright spec mocking /api/live + a controllable SSE stream to
drive the header icon strobe and the floating PiP open/close UX.
22 backend xUnit tests + 3 vitest assertions all green locally.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Unwrap draft PR body
Remove hard-wrapped prose from the draft PR description so GitHub renders paragraphs and list items without arbitrary line breaks.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Remove draft PR body file
Do not keep the temporary GitHub PR description file in source control.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Remove worktree cleanup scripts
The cleanup helpers were workflow-only artifacts and should not be source controlled.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add local live-status dev controls
- Enable an explicit AppHost local dev mode for live-status testing.
- Add dashboard HTTP commands on the StaticHost resource to fake Twitch
and YouTube live events, including signed calls to the real webhook
endpoints.
- Keep provider workers idle when API credentials are absent so local
state only changes when commanded.
- Fix the live-status JSON contract to emit youtube, matching the
frontend client, and add coverage for that shape.
- Document dashboard-command and manual HTTP testing paths.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Secure live dev commands and native PiP
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Keep live PiP open across navigation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Build frontend directly into StaticHost
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Keep live PiP alive across site navigation
Enable Astro client routing so same-origin site links swap content without unloading the opener document that owns the native Document Picture-in-Picture window. Update the live-status e2e coverage to click a real internal Docs link and assert the PiP iframe remains intact.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Let users choose live PiP source
When both Twitch and YouTube are live, show an explicit live-source menu from the header action before opening native Picture-in-Picture. Keep the selected source sticky while it remains live and allow switching an existing PiP window without recreating it.
Also replace noisy iframe title attributes on the live embeds with aria-labels so the videos tabs keep an accessible frame name without hover title noise.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Polish live stream chooser
Add YouTube and Twitch icons to the live-source chooser and remove the redundant aspiredotdev helper text. Rename the Community sidebar entry and related live destination copy from videos to Live Streams.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Fix live UX navigation regressions
Preserve the cookie consent root across Astro client-side body swaps so preferences continue to open after navigation. Restyle the live source chooser to align with the existing install modal treatment and cover the cookie regression with Playwright.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add live stream action dialog
Always show the live chooser while live so users can pick native PiP, the aspire.dev embeds, or the provider platform directly. Add a session-scoped dismiss action that silences the strobing live notification for the current live event without hiding the live entry point.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Fix live dialog mobile layout
Keep the live action dialog within narrow viewports and add mobile E2E coverage using mocked live status APIs. Also keep generated StaticHost output out of Debug build item discovery so local AppHost starts remain fast.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Polish live dialog responsive behavior
Make repeated live icon clicks toggle the live dialog, render the mobile dialog as a stable full-width sheet, restore a wider desktop menu with one-line labels, and harden mocked live-status E2E coverage for both layouts.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Move mobile live dialog below header
Anchor the mobile live action dialog below the top navigation instead of using a bottom sheet, add a top-right dismiss button matching the Install CLI modal affordance, and update E2E coverage for placement and dismiss behavior.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Polish live actions and notification sessions
Use regular Fluent icon names for local live command actions, reorganize the live action dialog into PiP, embedded-player, and platform groups, add external-link affordances, and introduce a stable liveSessionId so dismissing a live notification covers near-simultaneous provider joins.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Fix compact header regression expectation
Account for the live status header action in the compact header reachability test and map it by tour target so the assertion remains stable when live-state labels change.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add StaticHost live unit coverage
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Address live status PR feedback
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* * PR feedback
* fixup
* Fix API reference search controllers under view transitions
The six API reference page templates initialized their search controllers
inside a `DOMContentLoaded` listener. After this branch adds the
`<ClientRouter />` to `Head.astro` (so the live PiP can persist
across navigation), the site swaps bodies via view transitions and
`DOMContentLoaded` does not refire on subsequent navigations. As a
result, clicking the C#/TypeScript API buttons from the global search
dialog landed on the API page with the URL `?q=` parameter in place but
the controller was never instantiated, so `#ts-api-search-input` (and
its C# counterpart) was never populated and search results were never
rendered.
Switch all six API reference page initializers to `astro:page-load`,
which fires on the initial load and after every view-transition swap.
This matches the convention already used by `Sidebar.astro`,
`PageTitle.astro`, `InstallCliModal.astro`, and the rest of the
post-ClientRouter components in this branch.
Resolves:
tests/e2e/site-search.spec.ts:200 'typed query is forwarded to the
C# and TypeScript API buttons' (desktop / tablet / mobile chromium).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Address PR review feedback for live-status
Backend (StaticHost):
- Broadcaster: seed+register subscribers atomically under the lock so a flush
landing mid-subscribe can't strand a client on the stale seed; resolve sticky
primary against the pending basis so the first source stays primary when a
second joins within the coalesce window; ignore UpdatedAt when deciding whether
anything substantive changed so an ever-advancing timestamp can't force a
redundant broadcast.
- Twitch webhook: reject stale/unparseable Message-Timestamp (10-min window, 1-min
future skew) to bound replay of genuinely-signed callbacks; skip message-id dedup
for verification handshakes so retried challenges always echo; inject TimeProvider.
- YouTube webhook: replace the untracked per-notification Task.Run with a bounded,
coalescing YouTubeLiveConfirmationQueue BackgroundService (capacity-1 DropWrite)
tied to the host stopping token.
- Reconcile loops: only swallow OperationCanceledException when the stopping token
actually fired, so genuine cancellations elsewhere still surface.
- Cache-Control: no-store now applied centrally to the whole /api/live group via an
endpoint filter instead of per-handler.
Frontend:
- Seed fetch no longer clobbers fresher SSE state (apply only when not older).
- Tabs: only trusted (real user) clicks make a tab sticky, so auto-switch keeps
working; synthetic activateTab() clicks are ignored.
- build-static-host: restore scalar/.gitignore in finally before the temp dir is
removed, so a failed astro build can't lose the only preserved copies.
- Dev proxy: AppHost injects StaticHost's origin (ASPIRE_STATICHOST_URL) and Vite
proxies /api/live[/stream] to it under `aspire run`; omitted in CI/prod.
- Playwright: fulfil the SSE route with a complete string body via a shared helper
instead of a ReadableStream that serialised to garbage.
Tests:
- Broadcaster: coalesce-window primary stickiness and no-op suppression regressions.
- TwitchWebhookHandler.IsFresh: fresh/stale/skew/unparseable.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Fix botched merge in Header.astro cookie consent
The merge left Header.astro importing the removed `vanilla-cookieconsent`
package, breaking the frontend build. upstream/main replaced that package
with a global `[data-cookie-manage-consent]` handler in Head.astro
(`siteConsent.manageConsent()`), so drop the stale import and script and
keep only the live-status wiring.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Add seoTitle to videos page to satisfy SEO length guard
The redesigned videos page composed an og:title of only 23 characters
("Aspire Live 📺 · Aspire"), below the 30-65 guard range enforced by
tests/unit/seo-lengths.vitest.test.ts. Add a verbatim `seoTitle`
override (55 chars, in the 50-60 optimal range) so the social-card title
stays keyword-rich without lengthening the visible page title.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Remove obsolete cookie-preferences SPA-nav e2e test
This PR-only test leaked into the merge without its `openCookiePreferences`
helper, causing a ReferenceError across all e2e shards. The helper asserted
the `#pm__title` vanilla-cookieconsent modal, but upstream/main removed that
library in favor of a global `[data-cookie-manage-consent]` delegated
listener (Head.astro) that survives client-side navigation by design. The new
mechanism is already covered by cookie-consent.spec.ts, so drop the stale test.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Harden live status production readiness
Back production stream settings with Azure Key Vault, make YouTube polling and WebSub quota-safe, and repair local proxy, client-navigation lifecycle, static asset, and autoplay behavior.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Ignore generated Aspire publish output
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Prefer provider handoff for mobile live streams
Keep Document Picture-in-Picture on desktop while touch-first devices use provider apps or the existing iframe page. Improve chooser focus, failure feedback, touch targets, and iframe permissions.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Update live command tests for Aspire 13.5
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Use read-only site secrets and reduce live-status overhead
Provision a shared siteconfig vault without secret values, preserve read-only references, reuse SSE frames and timers, and avoid redundant player and navigation work.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Use parameters for live configuration
Keep non-sensitive live-status settings as deployment parameters while retaining provider credentials and webhook signing keys as read-only Key Vault references.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Update ASP.NET Core OpenAPI package
Use Microsoft.AspNetCore.OpenApi 10.0.12 so StaticHost resolves a current, non-vulnerable Microsoft.OpenApi dependency.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Isolate live status scaling
Keep the public StaticHost on Aspire's normal per-site worker ceiling and proxy live-status traffic to a dedicated single-worker coordinator.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Use Redis for distributed live status
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Rename live cache variable
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Load live secrets from Key Vault configuration
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Address live status review feedback
Use direct Redis optimistic concurrency for shared records, require distributed production services, clarify resource names and startup behavior, and share frontend brand tokens with Scalar.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Remove Redis key versions
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Address live status review feedback and coverage gaps
Preserve consent and API search ownership across navigation, fence YouTube observations, make WebSub retries idempotent, and refresh rejected Twitch tokens. Add mapped HTTP, Redis, and accessibility coverage and run backend suites in CI.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Use Aspire to manage Redis integration test infrastructure
Create the Redis-only application with DistributedApplicationTestingBuilder and the same Azure Managed Redis hosting integration as the AppHost. Remove the separate CI image pin, external connection-string contract, and shared-instance ownership guards.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Fix live embeds on staging and show YouTube uploads offline
Resolve Twitch parent from the browser hostname before loading, correct the shared Aspire YouTube channel, and switch between the non-autoplaying uploads playlist and exact live video. Cover source transitions, hidden tabs, and client navigation.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Eric Erhardt <eric.erhardt@microsoft.com>
Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com>
* docs: recreate language-neutral dev container guides Recreates #1627, including the certificate trust clarification and refreshed template screenshots. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs: remove unnecessary SDK aside from container guides Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Clears all open Dependabot alerts for src/frontend (1 critical, 6 high, 5 medium): - astro 7.1.3 -> 7.2.10 (critical GHSA + medium) - sharp 0.35.3 -> 0.35.4 (high) - vitest 4.1.10 -> 4.1.11; @vitest/mocker -> 4.1.11 (medium) - pnpm overrides: js-yaml 4.3.2, nanoid 3.3.18, svgo 4.1.0, fflate 0.7.5, smol-toml 1.7.1 Verified: pnpm install OK; pnpm audit -> no known vulnerabilities; astro sync OK. Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: restore site search after client-side navigation Initialize Pagefind per connected search element and dispose stale listeners and UI instances when navigating. Add navigation, history, API-page, and delayed-import regressions. Fixes #1673 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: preserve Mermaid layout across client navigation Keep Mermaid centering and responsive SVG sizing in the bundled stylesheet rather than relying on the plugin's one-time injected head style. Cover repeated navigation in light and dark themes on desktop and mobile. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: keep two-slash hover popups paired across navigation Replace competing plugin and inline hover initializers with one site-owned runtime that pairs each token with its generated popup and initializes each new page idempotently. Preserve rendered hover styles and Expressive Code tools. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: restore filters and history across client navigation Reinitialize API version, integration, and sample filters for each page and dispose outgoing listeners and debounce timers. Preserve Astro history state when filtering and avoid adding history entries during gallery initialization. Cover repeated navigation and Back on desktop and mobile. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * test: use the touch navigation fallback for site search Match the existing client-navigation suites by exercising native view transitions on desktop and ClientRouter's supported swap fallback on mobile and tablet. This prevents Chromium touch-emulation transition-abort exceptions from failing the strict search error assertions. Preserve all input, results, focus, history, and page-error checks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: aspire-repo-bot[bot] <268009190+aspire-repo-bot[bot]@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add scheduled CodeQL scanning Restore CodeQL coverage for the JavaScript/TypeScript frontend and C# AppHost on pushes, pull requests, and a weekly schedule. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22 * Scan the full C# solution with CodeQL Build every C# project in Aspire.Dev.slnx so CodeQL covers the AppHost, StaticHost, generator tools, and test projects. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22 * Avoid Aspire bundle setup during CodeQL build CodeQL only needs compiler extraction, so disable CLI bundle resolution while building the full solution. This keeps all C# projects covered without requiring orchestration assets. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22 --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22
…ts (#1681) * fix: preserve client navigation lifecycles across pages and deployments Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * refactor: replace plugin patches with site-owned UI Remove the Mermaid and scroll-to-top wrapper dependencies and their patches. Keep the existing Mermaid library, native controls, and explicit Astro lifecycle ownership. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs: keep JavaScript lifecycle details out of the contributor guide Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix formatting for mermaid error styles in CSS Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * fix: avoid competing cross-document transitions during deployment reloads Keep ClientRouter as the navigation owner. Stabilize CI viewport and transition assertions, and exercise native Document PiP in full Chromium. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: reset API title styles after navigation Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: restore navigation preferences before swap Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: address navigation lifecycle review Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * test: handle uppercase script tags Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: preserve effective Mermaid themes Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com>
* Improve YouTube live-status failure diagnostics Add safe operation-specific diagnostics, discovery observations, and fallback regression coverage without changing polling or retry policies. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Correct YouTube WebSub callback handling and diagnostics Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Correct YouTube quota bucket guidance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address YouTube diagnostic review feedback Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reconcile navigation, Mermaid rendering, deployment guards, and Live status diagnostics while retaining Dev Hub, release docs, and official blog updates. Combine Vite redirect definitions with the StaticHost proxy and cover both proxy states. Preserve pinned dependencies and exactly mirror the seven approved generated paths. Validation: 208 Live tests and 273 frontend tests pass; pinned pnpm frozen-lockfile install and 366 E2E test discovery pass. PENDING DATA VALIDATION: pinned main contains duplicate Floci integration rows rejected by the release catalog. Keep strict validation; do not publish or land until corrected canonical main is merged and catalog tests pass. Safeguards PR #1687 must land first. MUST MERGE; DO NOT SQUASH OR REBASE. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: address code scanning findings across previews and live endpoints Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: complete script tag recognition and markdown escaping Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: preserve useful sanitized Twitch diagnostics Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * test: separate verification secrets from diagnostic header fixtures Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Preserve safe webhook context and simplify table escaping Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The command `aspire add azure-app-configuration` doesn't work because the integration is actually named `azure-appconfiguration`.
* Harden release sync ancestry checks and conflict recovery Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Remove duplicate integration blocking release catalog sync Keep the generated Floci entry and reject duplicate package IDs in structured-data validation. The stale manually appended row prevented the release catalog from consuming main's mirrored data. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Merge main 1885cc4 after safeguards PR #1687 landed. Include canonical Floci uniqueness correction and security fixes; preserve intervening release/13.6 commit 732f999 and the original de85064 merge without rewriting history. Validation: 355 focused frontend tests, 36 structured-data tests, 235 Live tests, 7 release-sync fixture scenarios, and 25 OG preview tests pass. Strict catalog validation and seven-path generated parity pass. Previously frozen-validated package manifest and lockfile are unchanged. No local site build. MERGE COMMIT REQUIRED; DO NOT SQUASH OR REBASE. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Frontend HTML artifact readyThe latest frontend build uploaded the This comment updates automatically when a new frontend build artifact is uploaded. |
There was a problem hiding this comment.
🔵 Needs a closer look
It’s a large ancestry-repair merge touching critical workflows, frontend runtime behavior, and StaticHost production logging/security paths, which warrants final human/coordinator verification even though only minor code issues were found.
Pull request overview
This PR performs a one-time, ancestry-preserving repair of release/13.6 by merging in the pinned canonical main history (including the safeguards/data corrections) while keeping release-specific curated content and adding/refreshing validations and tests to prevent recurrence.
Changes:
- Introduces an explicit, test-covered “merge main into release” helper and wires it into CI / release update automation to preserve two-parent ancestry and enforce the curated-vs-generated merge policy.
- Hardens StaticHost Live (YouTube/Twitch) operational diagnostics: safe logging, bounded buffering, and clearer failure classification without leaking bodies/secrets.
- Updates frontend navigation/runtime behavior (deployment-boundary guard, Mermaid rendering, search excerpt extraction, pivots/scroll-to-top) and adds extensive unit + E2E coverage.
File summaries
| File | Description |
|---|---|
| tests/StaticHost.Tests/Live/YouTubeWebSubServiceTests.cs | Updates expectations to ensure exceptions aren’t attached to log entries. |
| tests/StaticHost.Tests/Live/YouTubeClientTests.cs | Adds tests validating HttpClient response buffering limits. |
| tests/StaticHost.Tests/Live/TwitchWebhookHandlerTests.cs | Adds regression tests ensuring Twitch webhook diagnostics are sanitized/bounded. |
| tests/StaticHost.Tests/Live/LiveTestHelpers.cs | Adds shared helpers for asserting “safe logs” (no injection/secrets). |
| tests/StaticHost.Tests/Live/InMemoryLiveStatusInfrastructure.cs | Extends in-memory test infra for new YouTube coordination/state scenarios. |
| src/statichost/StaticHost/Live/YouTube/YouTubeWebSubService.cs | Routes failures through new structured diagnostics and adds timing/last-discovery tracking. |
| src/statichost/StaticHost/Live/YouTube/YouTubeLiveConfirmationQueue.cs | Uses new diagnostics logging for confirmation failures. |
| src/statichost/StaticHost/Live/YouTube/YouTubeDiagnostics.cs | New diagnostics helper: safe failure classification, bounded body decoding, safe stack traces. |
| src/statichost/StaticHost/Live/YouTube/YouTubeClient.cs | Adds bounded response buffering and safe HTTP failure decoding via diagnostics helper. |
| src/statichost/StaticHost/Live/Twitch/TwitchWebhookHandler.cs | Sanitizes diagnostic fields and avoids logging raw revocation payloads. |
| src/statichost/StaticHost/Live/README.md | Documents new YouTube/Twitch operational diagnostics and safety guarantees. |
| src/statichost/StaticHost/Live/LiveStatusServiceCollectionExtensions.cs | Configures YouTube HttpClients with bounded MaxResponseContentBufferSize. |
| src/statichost/StaticHost/Live/LiveStatusOptions.cs | Clarifies discovery polling vs. quota enforcement in option docs. |
| src/statichost/StaticHost/Live/LiveEndpoints.cs | Adds denial-report handling, safer verification logging, signature behavior changes, and operation diagnostics. |
| src/frontend/tests/unit/update-integrations.vitest.test.ts | Adds case-insensitive uniqueness test for integration catalog package IDs. |
| src/frontend/tests/unit/search.vitest.test.ts | New unit tests for safe HTML excerpt-to-text extraction behavior. |
| src/frontend/tests/unit/sample-readme-headings.vitest.test.ts | Expands slug/heading plain-text regression coverage. |
| src/frontend/tests/unit/remark-mermaid.vitest.test.ts | New unit tests for custom Mermaid fence handling. |
| src/frontend/tests/unit/navigation-theme.vitest.test.ts | New unit tests validating theme preservation and view-transition ownership. |
| src/frontend/tests/unit/navigation-preferences.vitest.test.ts | New unit tests validating swap-time preference restoration and listener dedupe. |
| src/frontend/tests/unit/deployment-guard.vitest.test.ts | New unit tests for deployment-boundary navigation cancellation behavior. |
| src/frontend/tests/unit/custom-components.vitest.test.ts | Adds rendering assertions for the ScrollToTop component and translations. |
| src/frontend/tests/unit/astro-vite-config.vitest.test.ts | New tests ensuring Vite proxy config composes with redirect definitions. |
| src/frontend/tests/unit/api-search-lifecycle.vitest.test.ts | Improves controller script extraction via real HTML parsing (not regex). |
| src/frontend/tests/unit/api-markdown.vitest.test.ts | Adds robust coverage for Markdown table escaping (pipes/backslashes/newlines). |
| src/frontend/tests/unit/analytics-script-contracts.vitest.test.ts | Adds behavioral tests for analytics bootstrap/tracking binding and failure visibility. |
| src/frontend/tests/e2e/site-ui-navigation.spec.ts | New E2E validating Mermaid/scroll-to-top behavior across client swaps and history. |
| src/frontend/tests/e2e/site-search.spec.ts | Adds E2E coverage for styling correctness after API-search navigation. |
| src/frontend/tests/e2e/route-style-navigation.spec.ts | New E2E snapshot-style route rendering consistency across swaps/history. |
| src/frontend/tests/e2e/pivot-selector.spec.ts | Adds E2E coverage for pivot defaults, history preservation, and responsive floating controls. |
| src/frontend/tests/e2e/install-modal-navigation.spec.ts | New E2E ensuring modal listeners are single-bound and old controls are disposed. |
| src/frontend/tests/e2e/homepage.spec.ts | Stabilizes homepage interaction timing/scroll behavior assertions. |
| src/frontend/tests/e2e/deployment-navigation.spec.ts | New E2E validating same-deployment swaps vs cross-deployment full navigations + PiP behavior. |
| src/frontend/src/utils/sample-readme-headings.ts | Tightens slugify contract to operate on plain text (not HTML). |
| src/frontend/src/utils/api-markdown-shared.ts | Makes table-cell escaping preserve rich Markdown/code spans while escaping delimiters. |
| src/frontend/src/styles/site.css | Removes global @view-transition { navigation: auto; } to avoid double opt-in. |
| src/frontend/src/styles/mermaid.css | Adjusts Mermaid styling and adds error styling. |
| src/frontend/src/scripts/search.ts | Switches excerpt decoding to inert template parsing instead of tag-regex stripping. |
| src/frontend/src/scripts/mermaid.ts | New lazy Mermaid renderer that’s swap/theme aware and avoids duplicate rendering. |
| src/frontend/src/scripts/deployment-guard.ts | New client-side guard to force native navigation across deployment boundaries. |
| src/frontend/src/data/aspire-integrations.json | Updates generated integration data (downloads count, parity with pinned main). |
| src/frontend/src/content/docs/support.mdx | Updates support matrix and “last updated” badge. |
| src/frontend/src/content/docs/integrations/cloud/azure/azure-app-configuration/azure-app-configuration-host.mdx | Updates CLI install snippet and minor formatting/consistency. |
| src/frontend/src/components/starlight/PageTitle.astro | Makes API-title styling robust across client navigation by recomputing from window.location. |
| src/frontend/src/components/starlight/Head.astro | Adds deployment guard + Mermaid script imports and improves swap-time preference restoration. |
| src/frontend/src/components/starlight/Footer.astro | Adds ScrollToTop component to footer rendering. |
| src/frontend/src/components/ScrollToTop.astro | New custom scroll-to-top component with localized labels and swap-safe listeners. |
| src/frontend/src/components/pivot-selector.ts | New pivot-selector custom element with swap/history/persistence handling. |
| src/frontend/src/components/InstallCliModal.astro | Reworks modal listener binding using AbortController and cleans up on swaps. |
| src/frontend/public/scripts/analytics/track.js | Reduces debug noise and ensures failures are visible (warn). |
| src/frontend/public/scripts/analytics/1ds.js | Adds unload exclusion and improves failure logging (warn). |
| src/frontend/pnpm-lock.yaml | Removes obsolete Mermaid/scroll-to-top packages and locks updated dependency graph. |
| src/frontend/package.json | Removes astro-mermaid and starlight-scroll-to-top dependencies. |
| src/frontend/config/remark-mermaid.mjs | New remark plugin converting Mermaid fences into renderable <pre class="mermaid">. |
| src/frontend/config/icon-packs.mjs | Updates comments to reflect new lazy Mermaid icon-pack loading path. |
| src/frontend/astro.config.mjs | Replaces astro-mermaid integration with remark plugin + runtime renderer; composes Vite proxy config. |
| .github/workflows/update-release-branch.yml | Switches to running the merge helper from pinned main SHA. |
| .github/workflows/og-preview-tests.yml | New workflow to run OG preview extension tests. |
| .github/workflows/codeql.yml | Adds CodeQL scanning workflow for JS/TS and C#. |
| .github/workflows/ci.yml | Adds release-sync-tests job and gates CI on it. |
| .github/scripts/test-merge-main-into-release.sh | New regression suite covering release merge policy + ancestry preservation. |
| .github/scripts/merge-main-into-release.sh | New merge helper enforcing generated/curated policy and two-parent merge commit requirement. |
| .github/extensions/og-preview/ui/app.js | Adds capability-keyed API URL builder and improves origin/scheme validation + browse key handling. |
| .github/extensions/og-preview/tests/server.test.mjs | New end-to-end server tests covering capability isolation and safe error behavior. |
| .github/extensions/og-preview/tests/request-access.test.mjs | New tests for capability-based access control rules. |
| .github/extensions/og-preview/tests/http-fetch.test.mjs | New tests for SSRF hardening, DNS pinning, redirects, and scheme validation. |
| .github/extensions/og-preview/tests/fixtures/sdk.mjs | Test fixture for Copilot SDK wiring in OG preview tests. |
| .github/extensions/og-preview/README.md | Adds documentation on network isolation and capability model. |
| .github/extensions/og-preview/lib/request-access.mjs | New access-control helper implementing UI vs browse capability separation. |
| .github/extensions/og-preview/lib/http-fetch.mjs | Strengthens SSRF protections: explicit selection, DNS validation/pinning, scheme/credential rejection. |
| .github/extensions/og-preview/lib/agent-readiness.mjs | Ensures readiness probes respect authorized-origin policy and return fixed errors. |
| .github/extensions/og-preview/extension.mjs | Implements capability keys, origin selection, safer proxying, and fixed error responses. |
Review details
Files not reviewed (1)
- src/frontend/pnpm-lock.yaml: Generated file
- Files reviewed: 76/77 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| internal static string SanitizeDiagnosticValue(string value) | ||
| { | ||
| const int maxLength = 128; | ||
| var bounded = value.Length > maxLength ? value[..(maxLength - 3)] + "..." : value; | ||
| return Regex.Replace(bounded, "[^a-zA-Z0-9_.:+-]", "_"); | ||
| } |
MERGE COMMIT REQUIRED / DO NOT SQUASH OR REBASE
Target base:
release/13.6. This is the approved one-time ancestry-preserving repair, not an ordinary content PR. Preserve its merge commits. Do not squash, rebase, enable auto-merge, or bypass branch protections. Final landing requires an explicit merge-method/rules review by the coordinator.Prerequisite and pinned history
Safeguards PR #1687 has landed on canonical main. This repair includes its canonical commit,
1885cc47b41b1891a27eb534ba7475319aa6d0d8, including the Floci duplicate correction and strict catalog-uniqueness validation.Earlier repairs #1668 (
e31adede) and #1680 (4bc9c943) landed as single-parent commits, losing the original main merge ancestry and repeatedly surfacing already-resolved conflicts. This branch preserves real ancestry:de850648e25a88039e7731d197619ce0af4232ae, parents releaseca89b7463c96fd1027ca8103ab37a8f37f6dda74and main26d319119c731f652297780648754d4549873825.5cf4aef2e5ef4db7fd7dd977bca9225504ff7ee9, incorporates latest release732f999c1a1a63682ec29941221a8d9fd55cca2dwithout rewriting the original merge.3117d4264552c9cf01e9f3998b368aad9c5f88cc, parents5cf4aef2e5ef4db7fd7dd977bca9225504ff7ee9and1885cc47b41b1891a27eb534ba7475319aa6d0d8.The original merge's pending-data-validation note is resolved by the subsequent canonical-main merge. No unpublished safeguard commits were cherry-picked.
Preservation and semantic resolutions
src/frontend/src/data/{aspire-integrations.json,github-stats.json,samples.json,twoslash/aspire.d.ts,pkgs/**,ts-modules/**}andsrc/frontend/src/assets/samples/**. No broad data mirroring or new ownership policy.viteobject to overwrite the other; cover both proxy states.Validation
All local checks passed, without running a local site build:
Category!=RedisIntegration), with frontend build/install targets disabled.Full frontend build and browser execution are delegated to PR CI. Keep draft until CI passes and canonical heads are current; the coordinator will perform final merge-method/rule verification before landing with a merge commit.