Skip to content

fix(security): Update dependency @theia/workspace to ~1.69.0 [SECURITY] - #137

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-theia-workspace-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-theia-workspace-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 28, 2026 •

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@theia/workspace ~1.64.0 → ~1.69.0 age confidence

[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions

CVE-2026-44691 / GHSA-g9jw-92q7-g7fj

More information

Details

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat.

Severity

  • CVSS Score: 8.4 / 10 (High)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions

CVE-2026-44691 / GHSA-g9jw-92q7-g7fj

More information

Details

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat.

Severity

  • CVSS Score: 8.4 / 10 (High)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

eclipse-theia/theia (@​theia/workspace)

v1.69.0

Compare Source

  • [ai] declared agent-specific variable in claudeCode agent and improved agent specific variable status UX #​16967

  • [ai-anthropic] added support for custom anthropic models #​16673

  • [ai-anthropic] updated max tokens for opus 4.6 #​17051

  • [ai-anthropic, ai-core, ai-google, ai-openai] updated models #​17040

  • [ai-chat] added mode selector to ask AI input without session overhead or code duplication #​16914 - contributed on behalf of EclipseSource

  • [ai-chat] added showInChat property to control agent visibility in chat #​16925

  • [ai-chat] do not open editor on apply change #​16986

  • [ai-chat] fixed cannot configure tool confirmation mode if default is configured in package.json preferences #​17068 - Contributed on behalf of Lonti.com Pty Ltd.

  • [ai-chat] fixed: clear image context from chat input after sending #​16863

  • [ai-chat] improved usability of image file picker #​17018

  • [ai-chat] small ui improvements #​16952

  • [ai-chat-ui] added back/forward navigation between chats in the AI Chat View #​16894

  • [ai-chat-ui] added generic capabilities selection UI for chat requests #​17041

  • [ai-chat-ui] displayed images in chat request tree nodes #​17024

  • [ai-chat-ui] improved image variable semantics and behavior #​16902 - contributed on behalf of STMicroelectronics

  • [ai-chat-ui] improved tool call hover behavior and argument rendering #​16990

  • [ai-chat-ui] improved tool call parameters rendering #​16844

  • [ai-chat-ui] used bindRootContributionProvider for GenericCapabilitiesContribution #​17070

  • [ai-claude-code] implemented session-based tool approval for claude code #​16961

  • [ai-claude-code] supported for the AskUserQuestion functionality #​16981

  • [ai-copilot] ux improvements for GitHub copilot integration #​17059

  • [ai-core] added ./prompts/skills default to preference description #​17008

  • [ai-core] added capability variable for conditional prompt fragments #​16985

  • [ai-core] improved AI agent completion notifications #​17029 - contributed on behalf of STMicroelectronics

  • [ai-core] improved how to enable thinking mode #​17023

  • [ai-core] made opus 4.6 default in model aliases #​17066

  • [ai-core] passed toolCallId across RPC and normalized empty tool arguments #​16908

  • [ai-core] sorted the list by agent name and removed disabled agents #​16997

  • [ai-core] supported name and description for prompt fragments via frontmatter #​17048

  • [ai-core] watched parent directory for skills folder creation #​16927

  • [ai-history] showed prompt variant ID and edit state in history #​16876

  • [ai-ide] added cards for recent chat sessions to the Welcome screen #​16894

  • [ai-ide] added MCP server CRUD dialogs and slash commands to skills widget #​16991

  • [ai-ide] allowed Theia Coder Agent Mode to launch Apps #​17012

  • [ai-ide] consolidated coder prompts #​17004

  • [ai-ide] enhanced and refined capabilities #​17049

  • [ai-ide] fixed fileDiagnosticProvider to not open an editor #​17014

  • [ai-ide] fixed small improvements in AI agent config view #​16974

  • [ai-ide] fixed unread badge clearing all sessions when any chat is opened #​17045

  • [ai-ide] improved AI Chat welcome screen styling and UX #​17039

  • [ai-ide] made chrome dev App Tester default #​17042

  • [ai-ide] made new plan mode default #​17005

  • [ai-ide] Removed confusing escaping comment from function #​17006

  • [ai-ide] removed usage statistics from devtools mcp #​16943

  • [ai-ide] sorted agents alphabetically #​16979

  • [ai-ide] sorted alphabetically the MCP servers, variables, tools, and prompts lists #​16983

  • [ai-mcp] added roots support for mcp servers #​16911

  • [ai-ollama] yielded toolCallResponsePart before calling the tool handler #​16976

  • [ai-terminal] added shell command permission UI for AI terminal tool confirmation #​17054

  • [ai-terminal] added shell command whitelist for auto-approval #​16931

  • [ai-terminal] made shell command parser quote-aware #​17022

  • [api-samples] improved clarity of sample contributions #​16937

  • [ci] published next version on weekdays instead of only Mondays #​16989

  • [core] added a simple Card React component #​16894

  • [core] added locale and no-translate attributes to html element on startup #​16966

  • [core] changed 'no reply handler' from throw to console.warn #​16850 - contributed on behalf of es6kr

  • [core] fixed issue of preserving multiple consecutive spaces in theia ui elements #​16935

  • [core] fixed validation error messages in vscode.window.showInputBox and vscode.window.createInputBox #​17001

  • [core] fixed whitespace collapsing in explorer file/folder names #​16932

  • [core] improved containerBasedContributionProvider memory cleanup #​17021

  • [core] only set window.titleBarStyle preference if different from active value #​16425

  • [core] updated the dragdrop and widgets packages to the latest #​16970

  • [debug] prevented task execution and debug session creation without workspace trust #​16917

  • [debug] updated debug frame decoration logic #​16995

  • [dev-packages] merged the changes from the release branch to master #​16910

  • [editor] added formatter status bar with smart configuration management #​16829

  • [localization-manager] supported string concatenation and template literals in nls extraction and improved translation quality #​17035

  • [monaco] Called handleVisibilityChanged for embedded diff editor #​17009

  • [monaco] fixed search-in-workspace replace all failure for unopened files #​16945

  • [monaco] set model for embedded diff editors immediately #​16940

  • [plugin] fixed hostedPluginReader loads browser plugins relying on implicit .js resolution #​16886

  • [plugin-ext] fixed authentication session event chain #​16915

  • [plugin-ext] supported custom editors in the recently opened files list in files search quick pick #​16999

  • [preferences] scroll to focused item when search cleared #​16992

  • [prompts] mentioned npm and tasks in project info #​16973

  • [scm] improved merge conflict revealing #​16950

  • [scm] improved scroll state preservation #​16960

  • [scm] improved scroll sync implementation in merge editor #​16947

  • [scm] improved UX for merge conflict actions in special cases #​16980

  • [terminal] added optional trimRight parameter to TerminalBuffer.getLines to strip trailing whitespace used for terminal grid alignment #​16975

  • [terminal] synchronized onOutput with buffer updates using onWriteParsed #​16934

  • [ui] fixed debug console filter spellcheck and workspace trust dialog styles #​17015

  • [vscode] api evolution (public) and nls update to 1.109.4 #​17047

  • [vsx-registry] filtered versions for target platform in Extensions view #​17027

  • [workspace] ensured UNC paths are normalized correctly on Windows #​16712

  • [workspace] fixed minor css issues in workspace trust dialog and quick input list #​17063

  • [workspace] prevented restart dialog on startup for empty windows #​16924

  • [workspace] removed the seeding of workspace chat history from global history #​16933

  • [debug] reduced calls to provide dynamic debug configs #​16916

  • [terminal] fix TerminalBuffer.getLines to iterate in natural order instead of reversed order #​16975

  • [terminal] fix TerminalBuffer.getLines to use the start parameter instead of replacing it with 0 #​16975

v1.68.2: Eclipse Theia v1.68.2

Compare Source

Based on https://github.com/eclipse-theia/theia/tree/v1.68.2

Includes the following fixes:

Full Changelog: eclipse-theia/theia@v1.68.1...v1.68.2

v1.68.1: Eclipse Theia v1.68.1

Compare Source

Based on https://github.com/eclipse-theia/theia/tree/v1.68.1

Includes the following fixes:

Full Changelog: should be generated via 'Generate release notes'

Full Changelog: eclipse-theia/theia@v1.68.0...v1.68.1

v1.68.0

Compare Source

  • [ai-chat] added mode selection for coder and architect agents #​16860

  • [ai-chat] fix: do not break chat when interrupting tool calls #​16806

  • [ai-chat] fixed refresh bug after manual task context change #​16816

  • [ai-chat] fixed respect for agentId in delegateToAgent when prompt contains @​mentions #​16855

  • [ai-chat] fixed the failing test #​16897

  • [ai-chat] implemented preference for AI chat persisted session limit #​16776

  • [ai-chat] serialized and restored parsedChatRequest in chat sessions #​16736

  • [ai-chat] stored persistent chat sessions in the workspace by default #​16847

  • [ai-chat-ui] added toggle button to collapse changeset list #​16801

  • [ai-chat-ui] displayed prompt variant customization in chat view responses and agent config #​16749

  • [ai-chat-ui] enhanced chat accessibility (focus commands and ARIA) #​16835

  • [ai-chat-ui] highlighted referenced tools in users' chat messages #​16812

  • [ai-copilot] added GitHub Copilot language model integration #​16841

  • [ai-core] added agent skills support #​16810

  • [ai-core] updated default models #​16828

  • [ai-hugging-face] upgraded sdk to v4.x for new api endpoint #​16864

  • [ai-hugging-face] used patchLanguageModel to update model status #​16885

  • [ai-ide] added createSkill agent #​16903

  • [ai-ide] added Theia coder agent mode next prompt #​16799

  • [ai-ide] added todo tool function #​16859

  • [ai-ide] appTester improvements #​16898

  • [ai-ide] fixed misleading tool description for context_addFiles #​16778

  • [ai-ide] fixed model selection UI update for model alias #​16800

  • [ai-ide] fixed remote MCP server state and improved UX #​16822

  • [ai-ide] fixed selected item after model alias change #​16760

  • [ai-ide] improved architect planning mode - next prompt #​16843

  • [ai-ide] improved function descriptions #​16796

  • [ai-ide] improved task context variable description #​16817

  • [ai-ide] Reverted "Fixed #​16795 (#​16800)" #​16802

  • [ai-ide] switched writeFileReplacement to V2 replacer #​16815

  • [ai-mcp] blocked mcp server autostart in untrusted workspaces #​16891

  • [ai-mcp] updated MCP SDK to v1.25.1 and migrated to zod v4 #​16780

  • [core] added injectable LoggerSanitizer to mask sensitive data in logs #​16771 - Contributed on behalf of STMicroelectronics

  • [core] fixed memory leaks from 'toDisposeOn' disposable collections #​16856

  • [core] improved keybinding lookup and prioritization #​16763

  • [core] postponed default override warning logging until builtin preferences registered #​16853

  • [core] refactored tree search box into react widget and enhanced ux and styling #​16761

  • [core] restored enhanced tab preview for all widgets #​16895

  • [core] theia v1.67.0 released #​16738

  • [core] translation update for version 1.68.0 #​16907

  • [debug] fixed deletion of disabled source breakpoints #​16794

  • [debug] improved debug console with output persistence and text filtering #​16882

  • [doc] updated publishing guide documentation #​16768 - Contributed on behalf of STMicroelectronics

  • [examples] fixed clean script for the example applications #​16767

  • [github] added discussion auto-reply #​16746

  • [github] added sponsoring hint to discussion templates #​16745

  • [github] added sponsoring hint to gh ticket templates #​16744

  • [localization-manager] set deepl auth header #​16906

  • [messages] allowed copying messages from notifications and fixed copying of error messages in AI chat #​16830 - Contributed on behalf of STMicroelectronics

  • [messages] handled notification timeout correctly when set to 0 #​16849 - Contributed on behalf of STMicroelectronics

  • [monaco] updated built-in theme and color definitions #​16873

  • [output] fixed state restoration in outputWidget #​16851

  • [plugin] preserved lsp diagnostic.data in markers #​16766

  • [plugin] updated VS Code built-in extensions to 1.104.0 and Typescript to 5.9.3 #​16774 - contributed on behalf of STMicroelectronics

  • [preferences] marked llmprovider as experimental #​16784

  • [preferences] supported preference tags in settings view #​16783

  • [scm] added action button (commit button) support to scm #​16803 - contributed under the supervision of @​JonasHelming as part of the TUM Bachelor Thesis project "Enhancing Terminal Usability in Modern IDEs through AI-Assisted Interaction"

  • [scm] fix manual resolution not detected in some cases #​16869

  • [scm] fixed Go to Previous Unhandled Conflict doing nothing #​16838

  • [scm] fixed mark as handled having no effect in some cases #​16858

  • [scm] ux: fixed styling for scm commit button for high contrast themes #​16905

  • [terminal-manager] improved handling of terminal manager preferences & element deletion #​16827

  • [terminal-manager] updated active page handling on terminal page deletion #​16807

  • [vscode] API evolution (public and proposed) and nls update to 1.108.0 #​16871 - contributed on behalf of STMicroelectronics

  • [vsx-registry] fixed vsxExtensionsViewContainer onAfterAttach issue #​16862

  • [workspace] implemented workspace trust dialog and management #​16809

  • [workspace] improved computation of workspace trust for saved/multi-root workspaces #​16893

  • [workspace] updated dialog and status bar item styling and fixed command state handling #​16877

  • [monaco] refactored some of the fields in MonacoEditor and MonacoDiffEditor as part of #​16832:

    • changed the type of MonacoEditor.savedViewState from monaco.editor.ICodeEditorViewState | null to monaco.editor.IEditorViewState | null and also changed its visibility from public to protected
    • removed protected field MonacoEditor.model
    • removed protected fields savedDiffState, originalTextModel, and modifiedTextModel in MonacoDiffEditor
  • [preferences] Removed the optional 'knownCurrentValue' argument to PreferenceLeadNodeRenderer#updateModificationStatus. Renamed isModifiedInScope to isSet to reflect new semantics. #​16836

  • [core] removed oldValue and newValue fields from the PreferenceChange and the PreferenceProxy's PreferenceChangeEvent interfaces. The newValue field was a common footgun, as it represented the value in the changed scope rather than the effective value. In particular, it could be undefined when a given scope was cleared even if another scope provided a defined value. Use PreferenceService.get or PreferenceProxy.get or indexing on a PreferenceProxy to retrieve the active value rather than using the newValue field. #​16832

  • [scm] refactored some of the methods pertaining to the 3-way Merge Editor implementation as part of #​16867

    • removed the MergeEditorModel.findMergeRanges method
    • renamed the RangeUtils.isBeforeOrTouching method to isBefore
  • [ai-chat, ai-core] refactored tool handler context types #​16899: Tool handlers now receive ToolInvocationContext (with cancellationToken) instead of MutableChatRequestModel. Chat-bound tools should use assertChatContext(ctx) to access ChatToolContext with request and response properties.

  • [ai-chat] fixed: refactor tool handler context types for type safety #​16901

  • [ai-terminal] added shellExecutionTool for AI agents #​16878

  • [core] passed widget consistently to toolbar enablement handlers #​16826

v1.67.0

Compare Source

  • [ai-anthropic] added opus 4.5 to default models #​16656

  • [ai-anthropic, ai-core, ai-google, ai-openai] updated default models #​16636

  • [ai-chat] clarified role of Orchestrator agent in Theia AI chat interactions #​16663

  • [ai-chat-ui] ensured active session is recreated after deletion #​16702 - Contributed on behalf of Lonti.com Pty Ltd

  • [ai-claude-code] added session forking support #​16667

  • [ai-claude-code] migrated Claude Code to Theia native slash commands and modes #​16541

  • [ai-codex] added codex as an agent #​16484

  • [ai-codex] correctly asserted path for windows and linux tests #​16620

  • [ai-core] enableAgent/disableAgent: added async/await #​16599

  • [ai-core] enabled markdown syntax for prompt template files #​16557

  • [ai-core] fixed duplicate command check #​16718

  • [ai-core] handled undefined parameters for prompt template discard command #​16706

  • [ai-core] made opus 4.5 default in model alliasses #​16734

  • [ai-core] returned command by name if not found by ID #​16614

  • [ai-google] updated @​google/genai dependency, added thoughtSignature support and fixed content extraction #​16664

  • [ai-ide] added GitHub slash commands #​16704

  • [ai-ide] added remember command #​16639

  • [ai-ide] clicking on a file in ai context does not open file #​16468

  • [ai-ide] improved AI Agent Configuration view #​16698

  • [ai-ide] made next replacer function default #​16597

  • [ai-ide] updated command prompt template examples #​16608

  • [ai-llamafile] updated llamafile model status for agent availability #​16692

  • [ai-openai] recursively strictified tool call schemata #​16553

  • [ai-terminal] fixed unresponsiveness in ask AI terminal assistant #​16714

  • [application-package] bumped API compatibility to 1.106.1 #​16655 - Contributed on behalf of STMicroelectronics

  • [ci] fixed check-new-packages workflow and checkPublish script #​16650

  • [ci] migrated to npm trusted publishing (OIDC) and updated publishing workflow #​16630

  • [ci] optimized test builds to avoid redundant executions #​16552

  • [ci] set default values for scheduled publish-ci runs #​16695

  • [core] added support for emojis in markdown renderers #​16548

  • [core] fixed electron startup crash on wayland #​16658

  • [core] fixed the issue with exclude pattern in user settings not merging with workspace settings #​16483

  • [core] fixed workbench.startupEditor and scm.defaultViewMode reset behavior #​16646

  • [core] improved error handling in catalog.json download script #​16579 - contributed on behalf of STMicroelectronics

  • [core] improved menubar items active state handling on hover #​16586 - contributed on behalf of STMicroelectronics

  • [core] improved typing related to globalThis object #​16603

  • [core] npm upgrade #​16516

  • [core] provided markdown and localizedMarkdown components #​16470

  • [core] removed references to gitpod (now ona) #​16610

  • [core] restored tree expansion state preservation in SourceTreeWidget #​16654

  • [core] reverted "fix(core): restore tree expansion state preservation in SourceTreeWidget" #​16672

  • [core] reverted to scrollIntoView #​16532

  • [core] theia v1.66.0 released #​16515

  • [core] updated nls.metadata for vscode API 1.106.1 and added update eslint localization check #​16728 - contributed on behalf of STMicroelectronics

  • [core] updated package READMEs #​16631

  • [core] updated translations for 'applyAll' and 'finished' in Chinese locale #​16556

  • [core] used PreferenceService.get to merge agent settings from different scopes #​16612

  • [core] used undefined-safe deep equality check in preference updates #​16709

  • [customAgents] fixed default model for theia-dev #​16680

  • [debug] added breakpoint actions to debug view #​16700

  • [debug] added support for "lazy" debug variables #​16681

  • [debug] added support for adding the current editor selection to watch #​16567

  • [debug] added support for data breakpoints #​16505

  • [debug] opened stack frame editor on tap #​16519

  • [debug] variables made expandable when they should not #​16684

  • [dev-container] basic devcontainer docker compose support #​16577

  • [dev-container] fixed devContainer startup failure due to non-injectable logger #​16678

  • [doc] added coding guideline for localizing rich content #​16501

  • [doc] added i18n checklist item to PR template and review checklist #​16611

  • [doc] updated publishing guide #​16592 - Contributed on behalf of STMicroelectronics

  • [examples] fixed script parameters #​16523

  • [filesystem] fixed undefined error on context menu upload files command #​16600

  • [getting-started] enhanced localization of the package #​16578

  • [metrics] fixed error after deleting node_modules folder - cannot resolve package @​theia/ #​16602

  • [monaco] quick command panel not closing when pressing escape fixed #​16668

  • [notebook] "split editor" functionality for notebooks #​16507

  • [playwright] missing tslib import in @​theia/playwright #​16670

  • [plugin] API evolution (proposed) to 1.106.1 #​16626 - contributed on behalf of STMicroelectronics

  • [plugin] API evolution (public) to 1.106.1 #​16625 - Contributed on behalf of STMicroelectronics

  • [plugin-ext] fixed incorrect argument passing to StatusBarEntry #​16694

  • [plugin-ext] fixed issue with creating proper type instances in toSymbolInformation #​16731

  • [preferences] fixed: align input heights in preferences UI #​16733

  • [preferences] preference UI: subscribed directly to provider changes #​16506

  • [prompts] added two agents that allow for an agentic flow #​16473

  • [prompts] moved TheiaDev and TheiaDevCoder prompts to customAgents.yml #​16711

  • [terminal] enhanced localization of the terminal package #​16587

  • [terminal] new terminals were created in the panel of the clicked button #​16538

  • [terminal] when the terminal was inputting with a Chinese input method, the text that had already been input was covered #​16605

  • [terminal-manager] Adds new package providing a terminal manager widget to have multiple terminals within one view. Adds setting terminal.grouping.mode to switch between the
    old behavior and the new view. Default is the old behavior. #​16604

  • [terminal-manager] enhanced localization of the terminal-manager package #​16717

  • [terminal-manager] removed terminal flash animation on selection and cleaned up unused css rules #​16715

  • [timeline] updated proposed.timeline API and theia timeline view implementation #​16627 - Contributed on behalf of STMicroelectronics

  • [toolbar] improved icon picker dialog for adding toolbar items and updated @​vscode/codicons #​16629

  • [vsx-registry] used versioned id's for (un)installed and deployed plugins #​16513

  • [workspace] do not copy preferences that are valid in folder scope #​16622

  • [workspace] enhanced localization of the workspace package #​16589

  • [ai-core] objects returned by AiSettingsService settings retrievals marked readonly. To mutate a settings object, make a copy. #​16612

  • [core] CommonCommands has been extracted from common-frontend-contribution.ts into its own file common-commands.ts. This only affects code using deep imports: imports of CommonCommands from @theia/core/lib/browser/common-frontend-contribution should be updated to use the standard barrel export @theia/core/lib/browser instead.

  • [core] CommonMenus has been extracted from common-frontend-contribution.ts into its own file common-menus.ts. This only affects code using deep imports: imports of CommonMenus from @theia/core/lib/browser/common-frontend-contribution should be updated to use the standard barrel export @theia/core/lib/browser instead.

  • [core] moved CommonCommands to separate file #​16522

  • [debug] DebugSessionManager.getFunctionBreakpoints(), DebugSessionManager.getInstructionBreakpoints(), and DebugSessionManager.getBreakpoints() no longer default to the current session when called without arguments. Callers that relied on the implicit default to currentSession must now pass this.currentSession explicitly. #​16537

  • [debug] refactored some of the debug model elements as part of #​16689:

    • added required id parameter to DebugStackFrame and DebugScope constructors
    • changed type of keys in the DebugThread._frames map from number to string
    • added required startFrame parameter to DebugThread.doUpdateFrames method
  • [debug] some of the fields and methods of DebugToolBar have been removed in #​16719

  • [debug] moved Debug*Commands and DebugMenus to separate file #​16700

  • [plugin-ext] $setBadge method removed from WebviewsMain interface and WebviewsMainImpl; badge-related fields removed from WebviewView interface and implementation; badge-related fields removed from PluginViewWidget; badge-related fields removed from WebviewWidget. Use the BadgeService instead of BadgeWidget interface implementation to show extension badges. #​16518

  • [scm] ScmTabBarDecorator and bindings removed. ScmWidget now contributes badge decorations via the BadgeService. #​16518

v1.66.2: Eclipse Theia v1.66.2

Compare Source

Based on https://github.com/eclipse-theia/theia/tree/v1.66.1

Includes the following fixes:

Full Changelog: eclipse-theia/theia@v1.66.1...v1.66.2

v1.66.1: Eclipse Theia v1.66.1

Compare Source

Based on https://github.com/eclipse-theia/theia/tree/v1.66.0

Includes the following fixes:

Full Changelog: eclipse-theia/theia@v1.66.0...v1.66.1

v1.66.0

Compare Source

  • [ai-anthropic] allowed configuring proxy settings #​16453

  • [ai-anthropic] fixed Anthropic request errors when using parallel tool calls #​16359

  • [ai-chat] enhanced localization of the ai-chat package #​16409

  • [ai-chat] implemented chat session persistence #​16486

  • [ai-chat] refined the description of agent delegate tool #​16378

  • [ai-chat-ui] added mode support for chat agents #​16489

  • [ai-chat-ui] enhanced localization of the ai-chat-ui package #​16414

  • [ai-claude-code] added dedicated Claude Code API key preference #​16508

  • [ai-claude-code] enhanced localization of the ai-claude-code package #​16451

  • [ai-claude-code] migrated to claude agent sdk #​16500

  • [ai-code-completion] enhanced localization of ai-code-completion #​16416

  • [ai-core] added support for slash commands #​16444

  • [ai-core] enhanced localization of the ai-core package #​16350

  • [ai-editor] enhanced localization of ai-editor #​16416

  • [ai-google] conditionally included tools in GoogleModel based on functionDeclarations length #​16480

  • [ai-google] fixed google language model error for requests without tool functions #​16380 - Contributed on behalf of Lonti.com Pty Ltd

  • [ai-ide] adapted workspace functions preferences #​16452

  • [ai-ide] added GitHub agent #​16374

  • [ai-ide] added initial project info agent (alpha) #​16462

  • [ai-ide] added new content replacer strategy for coder edit mode #​16322

  • [ai-ide] added orchestrator agent exclusion list #​16510

  • [ai-ide] added support to suggest terminal command #​16428

  • [ai-ide] enhanced localization of the ai-ide package #​16426

  • [ai-ide] extracted task context prompt into separate agent #​16393

  • [ai-ide] fixed two minor spelling/wording issues with the coder prompt #​16402

  • [ai-ide] forbade meta comments in coder prompt #​16331

  • [ai-ide] removed @​theia/git dependency #​16465

  • [ai-mcp] added option to run a resolve operation on mcp server start #​16049

  • [ai-mcp] fixed preference categorization for MCP server preferences #​16346

  • [ai-mcp-server] added .js extension to imports for ESM to allow usage in commonjs #​16410 - Contributed by STMicroelectronics

  • [ai-openai] allowed configuring proxy settings #​16453

  • [ai-openai] used OpenAI response API #​16394

  • [ai-scanoss] fixed SCANOSS dialog expansion with long JSON content #​16485

  • [ai-terminal] enhanced localization of ai-terminal #​16416

  • [application-manager] resolved .node files in webpack backend config #​16377

  • [application-package] bumped vscode API compatibility to 1.105.0 #​16495

  • [ci] optimized CI build to avoid redundant executions #​16457

  • [ci] updated license workflow and switched to nodejs wrapper #​16456

  • [ci] updated publish-release workflow for release automation #​16433 - Contributed on behalf of STMicroelectronics

  • [core] added symbol icon default colors #​15860

  • [core] added z-index to dock layering style #​16375

  • [core] ensured reveal scrolls to selected tree row #​16463

  • [core] evaluated enablement and toggle state of command only once before showing context menu #​16325 - Contributed on behalf of Lonti.com Pty Ltd

  • [core] evolved vscode API (public) to 1.105.0 #​16476 - Contributed on behalf of STMicroelectronics

  • [core] fixed authentication service not reacting to session changes #​16252

  • [core] fixed tooltip/hover service mouseOut for non-chromium browsers #​16417

  • [core] fixed vscode plugin activation failed error when it uses an already existing key in its settings #​16481

  • [core] improved default value and reset handling for preferences #​16356

  • [core] prevented await identifiers #​16404 - Contributed on behalf of STMicroelectronics

  • [core] showed hover tooltip immediately when

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file security labels Aug 28, 2026
@renovate
renovate Bot force-pushed the renovate/npm-theia-workspace-vulnerability branch from 9b389a0 to 5ab9d33 Compare September 12, 2026 15:57
@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b2227c71-ab09-42eb-91ee-7408f118dbcb

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/npm-theia-workspace-vulnerability branch from 5ab9d33 to c075be1 Compare September 28, 2026 20:38
@renovate
renovate Bot force-pushed the renovate/npm-theia-workspace-vulnerability branch from c075be1 to 2b391b4 Compare October 3, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants