Skip to content

chore(deps): bump agentworkforce packages 4.1.56 → 4.1.60 - #146

Merged
khaliqgant merged 1 commit into
mainfrom
chore/bump-agentworkforce-4.1.60
Sep 30, 2026
Merged

khaliqgant merged 1 commit into
mainfrom
chore/bump-agentworkforce-4.1.60

Conversation

@khaliqgant

@khaliqgant khaliqgant commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Bumps every agentworkforce / @agentworkforce/* pin in package.json (dependencies, devDependencies, overrides) from 4.1.56 to 4.1.60, and regenerates package-lock.json. Only @agentworkforce/* / agentworkforce lock entries change.

Why

4.1.60 ships AgentWorkforce/workforce#342:

  • After agentworkforce login, deploy, deployments list and destroy now use the cloud workspace id. Previously they used the relaycast id, and cloud answered 403 when that id wasn't bound.
  • A relaycast workspace key (rk_…) in WORKFORCE_WORKSPACE_TOKEN is rejected up front with guidance, instead of a later 401.
  • agentworkforce login prints the cloud workspace id.

This matches the docs already corrected in #145.

Verification

  • npm test: 374/374 pass. npm run typecheck: ok. npm run compile: 15 personas compiled and registered.
  • node scripts/deploy/deploy-agents.mjs --agent hn-monitor --dry-run: ok.
  • Published-package E2E: clean npm i agentworkforce@4.1.60 with no overrides; all packages resolved at 4.1.60. login against our own workspace printed cloud workspace id: <uuid>. deployments list called GET /api/v1/workspaces/<cloud-uuid>/deployments → 200.

🤖 Generated with Claude Code


Note

Low Risk
Dependency-only bump; runtime behavior changes live in the published CLI packages, with verification noted in the PR description.

Overview
Bumps all pinned agentworkforce and @agentworkforce/* versions from 4.1.56 to 4.1.60 in package.json (dependencies, devDependencies, and overrides) and refreshes package-lock.json. Transitive updates include @relayfile/adapter-core (0.5.24 → 0.5.27 under runtime) and fast-uri (3.1.7 → 3.1.8); no application source in this repo changes.

This repo picks up 4.1.60 CLI/deploy behavior (workforce#342): post-login deploy, deployments list, and destroy use the cloud workspace id instead of the relaycast id (fixing 403s), WORKFORCE_WORKSPACE_TOKEN with a relaycast rk_… key fails fast with guidance, and login prints the cloud workspace id—aligned with docs from #145.

Reviewed by Cursor Bugbot for commit dd2a357. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Bumps all agentworkforce and @agentworkforce/* pins in package.json from 4.1.56 to 4.1.60 and regenerates package-lock.json. The new version fixes cloud API calls returning 403 after agentworkforce login, matching the docs already corrected in #145.

Behavior changes in 4.1.60:

  • agentworkforce login, deploy, deployments list, and destroy now use the cloud workspace id instead of the relaycast id.
  • A relaycast workspace key (rk_…) in WORKFORCE_WORKSPACE_TOKEN is rejected up front with guidance.
  • agentworkforce login prints the cloud workspace id.

Verified with tests, typecheck, compile, a dry-run deploy, and a clean npm i agentworkforce@4.1.60 E2E.

Written for commit dd2a357. Summary will update on new commits.

Review in cubic

4.1.60 includes AgentWorkforce/workforce#342: cloud API calls use the
cloud workspace id (fixes 403 on deploy / deployments list / destroy
after login), rk_ keys in WORKFORCE_WORKSPACE_TOKEN are rejected up
front, and login prints the cloud workspace id.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T07:55:36.328835Z dd2a357 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 16 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 993ca05c-130b-467f-a1f7-e0032767c693

📥 Commits

Reviewing files that changed from the base of the PR and between 33425a7 and dd2a357.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Devin Review: 1 flag

Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

@khaliqgant

Copy link
Copy Markdown
Member Author

Devin Review reported 1 flag but didn't post it to GitHub (repo settings), and I can't read it without an interactive Devin login. I checked the usual pin-bump risks myself instead:

  • engines and peerDependencies are identical between 4.1.56 and 4.1.60 for agentworkforce, cli, deploy, runtime, compose, delivery, persona-kit and local-surface
  • npm ls --all shows no invalid or missing packages
  • every lockfile entry resolves from registry.npmjs.org
  • test 374/374, typecheck, compile and the deploy dry-run all pass

One intended behaviour change: if the workforce environment secret WORKFORCE_WORKSPACE_TOKEN still holds an rk_… workspace key (the old docs' recipe), Deploy agent now fails fast with guidance instead of hitting a 401. That token never worked. Refresh the secret per docs/SELF-DEPLOY.md §2 (cloud access token + cloud workspace id).

@khaliqgant
khaliqgant merged commit 4127209 into main Sep 30, 2026
4 checks passed
@khaliqgant
khaliqgant deleted the chore/bump-agentworkforce-4.1.60 branch September 30, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant