Skip to content

chore(deps): move to zod 4 and the zod-4 @agent-relay lines - #343

Merged
willwashburn merged 3 commits into
mainfrom
claude/lucid-wozniak-8sixkk
Oct 2, 2026
Merged

willwashburn merged 3 commits into
mainfrom
claude/lucid-wozniak-8sixkk

Conversation

@willwashburn

@willwashburn willwashburn commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Supports AgentWorkforce/cloud#4080: cloud wants to converge on a single zod version. Cloud pulls @agentworkforce/deploy → @agentworkforce/runtime, and several deps in that chain still brought in zod 3.

The zod floor is ^4.4.3, so cloud can pin zod 4.4.3. zod 4.5.0 and later roughly double zod/v4/core (about +50 KB gzip). Cloud's Cloudflare Worker bundles zod about 5 times, so 4.5+ pushes it over the 10 MiB limit. The lockfile here resolves the whole tree to 4.4.3, so tests run against the version cloud will pin. Every zod-4 dependent in the tree accepts 4.4.3: @agent-relay/* 12.x (^4.4.3), @relaycast/* (^4.3.6), @modelcontextprotocol/sdk (^3.25 || ^4.0) and ai/@ai-sdk/* (^4.1.8).

Dependency changes

Package Dependency Before After
mcp-workforce zod ^3.23.8 ^4.4.3 (resolved 4.4.3)
mcp-workforce @modelcontextprotocol/sdk ^1.21.0 ^1.31.0 (peer zod ^3.25 || ^4.0)
deploy, cli @agent-relay/cloud ^10.1.0 ^12.2.2 (@agent-relay/config 12.x → zod 4)
local-surface @agent-relay/fleet ^11.5.0 ^12.2.2
runtime @agent-relay/events ^6.3.3 ^7.1.1
runtime, root (dev) agent-trajectories ^0.5.3 ^0.5.3 || ^0.6.0 || ^0.7.0

The lockfile now resolves @agent-relay/* to 12.4.1, agent-trajectories to 0.6.1 and zod 4 to 4.4.3 everywhere.

Code changes

  • mcp-workforce: the schemas already worked with zod 4 (z.record(z.string(), …), no errorMap, .errors or _def), so no source change was needed. I added a test that connects over the in-memory MCP transport. It checks that tool input schemas are listed as JSON Schema (required, minLength, enum) and that a call with invalid input is rejected. It passes with zod 4.4.3 resolved.
  • runtime trajectory.ts: the type declarations in agent-trajectories 0.5.5–0.6.x leave workflowId out of CreateTrajectoryInput. Every release still reads it at runtime, and trajectories main (0.7) declares it again. The start options are now built in a separate variable to get past the excess-property check. A new test checks that workflowId ends up on the raw trajectory.
  • local-surface: the spawn:persona compatibility guard and README now require @agent-relay/fleet 12 or newer, matching the new dependency. The guard reads the installed Fleet major version and falls back to the FLEET_DYNAMIC_SPAWN_DELEGATION flag when the manifest can't be read. No Fleet export separates 12.x from 11.8+, so the guard reads the version directly. Tests cover both paths.
  • No API changes were needed for @agent-relay/cloud, fleet or events.

Remaining zod 3 in the production tree

  • agent-trajectories 0.6.1, which uses zod 3. This goes away once trajectories 0.7.0 (zod 4) is released, and the widened range already allows it.
  • Dev-only, not shipped: the @agent-assistant/* devDependencies in turn-kit still bring in older @agent-relay/sdk 4.x/6.x and zod 3.

Testing (Node 26.5.0, same as CI)

  • pnpm install --frozen-lockfile, build, pnpm run lint, pnpm run typecheck, scripts/*.test.mjs and test:e2e:agent-card all pass.
  • pnpm -r test: everything passes except deploy's runtime-credentials-live.test. That test calls production agentrelay.com, which the sandbox's egress proxy blocks, so it got 403 instead of 401. It is unrelated to this change.

🤖 Generated with Claude Code

https://claude.ai/code/session_015pwJbZ21p1TB7MRHXdYjG3


Note

Medium Risk
Major bumps on @agent-relay/cloud, fleet, and events plus a breaking Fleet 12 floor for spawn:persona affect install graphs and local Relay deployments; trajectory typing is a compile-time workaround with runtime behavior unchanged.

Overview
This PR moves the monorepo onto zod 4.4.3 (root pnpm override zod@^4 → 4.4.3) so consumers like cloud can dedupe without pulling zod 3, and bumps @agent-relay/* to zod-4 lines: @agent-relay/cloud ^12.2.2 (cli/deploy), @agent-relay/fleet ^12.2.2 (local-surface), @agent-relay/events ^7.1.1 (runtime).

@agentworkforce/mcp-workforce upgrades @modelcontextprotocol/sdk to ^1.31.0 and zod to ^4.4.3; a new integration test asserts MCP tool schemas are JSON Schema and invalid calls are rejected.

@agentworkforce/runtime widens agent-trajectories to ^0.5.3 || ^0.6.0 || ^0.7.0 and adjusts trajectory start options so workflowId is passed despite missing types in 0.6.x, with a test that the raw artifact carries it.

spawn:persona in local-surface now requires Fleet major 12+: README updated, and a runtime guard checks FLEET_DYNAMIC_SPAWN_DELEGATION plus a memoized read of the installed @agent-relay/fleet version (capability-only when the manifest is unreadable). Tests cover version rules and memoization.

CHANGELOG documents the dependency and compatibility shifts; lockfile resolves relay 12.4.1, trajectories 0.6.1, and zod 4.4.3 across the tree.

Reviewed by Cursor Bugbot for commit e675ea7. Bugbot is set up for automated code reviews on this repo. Configure here.

- mcp-workforce: zod ^3.23.8 -> ^4.6.5, @modelcontextprotocol/sdk ^1.31.0;
  add an MCP-protocol test that the zod schemas list as JSON Schema and
  reject invalid input.
- deploy/cli: @agent-relay/cloud ^10.1.0 -> ^12.2.2; local-surface:
  @agent-relay/fleet ^11.5.0 -> ^12.2.2; runtime: @agent-relay/events
  ^6.3.3 -> ^7.1.1.
- runtime + root: agent-trajectories ^0.5.3 -> ^0.5.3 || ^0.6.0 || ^0.7.0
  so consumers can dedupe on the zod-4 trajectories release. The
  0.5.5-0.6.x type declarations omit CreateTrajectoryInput.workflowId
  (still honored at runtime), so the start options are built outside the
  call; a test now asserts the workflowId is stamped.
- Lockfile: collapse the remaining zod 4.4.3 copy onto 4.6.5.

Supports AgentWorkforce/cloud#4080.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015pwJbZ21p1TB7MRHXdYjG3
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T18:28:56.708016Z 8f76d00 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 16 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 350dad5f-3e32-462e-ab3c-f8b87b5fc9ae

📥 Commits

Reviewing files that changed from the base of the PR and between 8f76d00 and e675ea7.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (6)
  • CHANGELOG.md
  • package.json
  • packages/local-surface/README.md
  • packages/local-surface/src/persona-spawn.test.ts
  • packages/local-surface/src/persona-spawn.ts
  • packages/mcp-workforce/package.json

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 91a0f56f-07c2-43e1-85d7-19e809f25e51

📥 Commits

Reviewing files that changed from the base of the PR and between 101d19d and 8f76d00.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (10)
  • CHANGELOG.md
  • package.json
  • packages/cli/package.json
  • packages/deploy/package.json
  • packages/local-surface/package.json
  • packages/mcp-workforce/package.json
  • packages/mcp-workforce/src/server.test.ts
  • packages/runtime/package.json
  • packages/runtime/src/trajectory.test.ts
  • packages/runtime/src/trajectory.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Dependency ranges change for MCP, Agent Relay, and agent-trajectories packages. Runtime trajectory start options now require workflowId, and tests check MCP tool schemas and recorded trajectory data.

Changes

Dependency and MCP protocol checks

Layer / File(s) Summary
Dependency versions and MCP protocol checks
CHANGELOG.md, package.json, packages/*/package.json, packages/mcp-workforce/src/server.test.ts
Dependency ranges change for the MCP SDK, zod, Agent Relay packages, and agent-trajectories. The protocol test checks advertised tool schemas and rejects an empty runId for workflow.status.

Trajectory recording

Layer / File(s) Summary
Typed trajectory start options
packages/runtime/src/trajectory.ts, packages/runtime/src/trajectory.test.ts
Trajectory start options require workflowId. A regression test checks that raw trajectory records matching a compacted contract have the expected workflowId.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Suggested reviewers: khaliqgant

Merge Risk: ⚪ Minimal · up to 8f76d

This PR updates dependency ranges and adds tests without changing runtime behavior, and no concrete merge-blocking issue was found. Normal CI should still confirm that the dependency upgrades install and build cleanly.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 8f76d

This is primarily a dependency-compatibility change. The local refactor preserves existing behavior, and no introduced security bypass is established. Compatibility across all supported dependency versions and failure states remains only partially verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The inspected recorder uses a configured trajectory root and persona ID for SDK storage and compacted output. Recording is disabled when no root resolves. This establishes the local storage scope, not deployment-wide tenant isolation or exclusivity between processes.

Trust Boundaries and Controls

  • observed — Event-derived workflow identity and workspace/source tags continue to enter the existing SDK start call. The workflow-ID helper replaces non-alphanumeric characters other than underscore and hyphen in the event ID. This normalization is not an authorization or tenant-isolation control.
  • observed — MCP workflow registration retains nonempty-string schemas for workflow names and status run IDs before delegating arguments to handlers. The inspected registration does not itself establish downstream workspace authorization.

Resilience and Maintainability Implications

  • observed — Existing session and finalized guards prevent repeated sequential terminal calls, and the done-then-complete test checks single-artifact behavior. These controls do not prove safe overlapping begin calls or exclusive ownership of persona-scoped active storage.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 3 files. (7 skipped: 7 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the main dependency changes: migration to zod 4 and zod-4-compatible @agent-relay packages.
Description check ✅ Passed The description is directly related to the dependency upgrades, compatibility changes, tests, and known test limitation.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the schemas at dawn,
Then hops where new dependencies spawn.
It tags each trail with workflowId,
And finds the matching paths inside.
A carrot waits beside the test.

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 11 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread packages/local-surface/package.json
- mcp-workforce: zod ^4.6.5 -> ^4.4.3 and resolve the whole lockfile to
  zod 4.4.3 so cloud can pin 4.4.3 (4.5+ roughly doubles zod/v4/core and
  pushes the cloud Worker over its size limit). Every zod-4 dependent in
  the tree accepts 4.4.3.
- local-surface: the spawn:persona compatibility guard and README now
  require @agent-relay/fleet 12+, matching the ^12.2.2 dependency. The
  guard checks the installed Fleet major (falling back to the capability
  flag when the manifest is unreadable); tests cover both paths.

Supports AgentWorkforce/cloud#4080.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015pwJbZ21p1TB7MRHXdYjG3

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 6 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread packages/mcp-workforce/package.json
Comment thread packages/local-surface/src/persona-spawn.ts
- Root pnpm.overrides `zod@^4: 4.4.3` so lockfile regeneration in this
  repo cannot drift to zod 4.5+. The published mcp-workforce range stays
  ^4.4.3 so consumers are not forced into duplicate zod copies.
- local-surface: the spawn:persona guard reads the installed Fleet
  version once per process (undefined results cached too) instead of
  doing sync fs I/O on every action; covered by a test.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015pwJbZ21p1TB7MRHXdYjG3
@willwashburn
willwashburn merged commit fc21099 into main Oct 2, 2026
4 checks passed
@willwashburn
willwashburn deleted the claude/lucid-wozniak-8sixkk branch October 2, 2026 04:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants