Repository navigation
chore(deps): bump the all-actions group with 2 updates - #1
Merged
github-actions[bot] merged 20 commits intoJul 25, 2026
Merged
Conversation
…eting - Rename package to "browser-controller" and bump version to 2.0.0 - Introduce multi-client daemon allowing multiple agents simultaneously - Implement explicit tab targeting for all interactions with required tabId - Add tab locking/unlocking to serialize access and avoid racing conditions - Switch browser_evaluate to main world execution without debugger banner - Use authenticated WebSocket for secure extension-daemon communication - Restructure internal server and extension architecture for concurrency support - Expand toolset from 18 to 22, including file upload and drag actions - Provide clear errors if tabId is missing on multi-tab tools - Update documentation, examples, and agent configs to reflect v2 model - Add daemon files and token management for connection authentication - Remove libc-related fields from package-lock for compatibility - Update README with detailed architecture, quick start, and usage steps
- Add autoPairToken to fetch and store daemon auth token at startup and reconnects - Detect bad or missing tokens by tracking handshake-close events and auto re-pair before reconnect - Introduce autoReSnapshot to capture fresh DOM refs on virtualized feed errors for retry - Enhance click and type handlers to abort on element removal, trigger auto re-snapshot, and embed fresh refs - Add refsMayBeStale flag on successful scroll indicating potential DOM recycling - Pass fallback generator functions as source strings and reconstruct in page context due to serialization limits - Create a minimal CLI driver script (drive.mjs) to authenticate and send commands to daemon via IPC socket
- Add .graphify_labels.json mapping node IDs to names - Include .graphify_root file indicating graph root directory - Add GRAPH_REPORT.md summarizing graph structure and insights - Add graph.html visualization with interactive elements and styles - Provide node details, community grouping, and connectivity stats - Document surprising inferred edges and isolated nodes information
…dling - Replace real-browser-mcp rule with browser-controller in setup and docs - Add .graphifyignore to skip image files and graphify output directories - Modify extension background message listener for synchronous responses - Silence benign warnings in content script to reduce console spam - Update graphify analysis and report files with expanded community insights
- Add "Agent Config" as a new community with 7 nodes - Increase total nodes from 438 to 446, edges adjusted accordingly - Update graph report date, commit hash, and corpus statistics - Adjust cohesion scores and node listings for several communities - Rename graph title in HTML to reflect accurate workspace path - Fix minor formatting in JSON graph labels for readability
- Remove image file extensions from .graphifyignore - Add comments about Z.ai Anthropic endpoint extracting images now - Retain exclusion of generated graphify output directory - Update stat-index.json cache file with latest metadata changes
- Added new nodes and rearranged existing nodes into 28 communities from 24 - Renamed community labels for clarity and consistency - Increased total node count from 446 to 456 and edges from 709 to 715 - Updated cohesion scores reflecting community restructuring - Added new hyperedges including App Icon Asset Family and Brand Visual Assets - Introduced new questions identifying bridge nodes, inferred edge verification, and cohesion concerns - Refreshed signature hashes for label file - Updated graph HTML title and stats to reflect new graph structure
- Replace "questions" array with "tokens" object in .graphify_analysis.json - Rename multiple community names for clarity and consistency - Update built_at_commit hash in graph.json file - Modify community names from legacy to new standard labels - Change "Agent Config" community to "README Documentation" - Rename "background.js" to "Extension Background Service" - Rename "content.js" to "Content Script" - Adjust naming for TabLockMap to "Tab Concurrency Lock" - Rename "Extension Bridge Client" to "Extension Bridge Logic" - Standardize other community label names for accuracy
…ate docs - Rename project and agent config from `real-browser-mcp` to `browser-controller` (v2.0.0) - Update core architecture and usage documentation to reflect new name and architecture - Add detailed info on three-piece architecture, concurrency model, and element identification layers - Expand tool inventory and tab-targeting model descriptions, include new tools and behaviors - Change browser_evaluate to use chrome.scripting MAIN world for CSP safety and no debugger banner - Modify extension background service and add notes on serialization gotchas and element refs - Update agent-config setup scripts and README references to new project name - Improve graphify metadata and community cohesion details to reflect codebase changes
…oller - Updated product name in CHROME_WEB_STORE.md, PRIVACY.md, and README.md - Revised all references to "Real Browser MCP" to "Browser Controller" for consistency - Clarified usage steps and descriptions in agent configuration and skill docs - Enhanced snapshot feature with `isNew` tagging for new elements since last snapshot - Improved fallback selector with `nth` ordinal to resolve correct sibling elements - Added automatic ref recovery and freshRefs retry mechanism after DOM changes - Cleaned up and strengthened background service for snapshot fingerprint tracking - Updated smart-selector utilities to support `nth` matching and new fingerprint logic
- Added new labels for scripts, dependencies, files, and repository - Updated corpus word count and altered edges and communities count - Improved community cohesion and nodes distribution - Added new communities for scripts, dependencies, files, and repository - Revised knowledge gaps and cross-community bridge nodes descriptions - Updated graph HTML stats to reflect new node, edge, and community counts
…cleanup - Replace existing agent with same name on new connection to prevent duplicates - Add periodic ping messages to clients every 15 seconds to detect dead connections - Automatically destroy sockets missing three consecutive pongs (~45 seconds) - Enable TCP keep-alive to detect half-open sockets faster - Add GET /kill endpoint to forcibly disconnect clients by sessionId - Enhance IPC protocol with ping/pong messages for liveness checks - Improve agent name detection using parent process inspection - Correct daemon log path for consistent log storage feat(extension): add tab pinning UI and tab lock management in popup - Add "Open Tabs" section in popup listing all tabs with pin/unpin controls - Implement dropdown to select agent for pinning each tab and lock/unlock buttons - Display locked tabs with lock owner and unpin button - Add disconnect button for each connected agent to forcibly remove zombie agents - Update popup to refresh tabs, locks, and agents state every 2 seconds asynchronously - Send lockTab/unlockTab messages from popup to background for tab lock state changes - Show lock status and owners in popup with friendly agent labels feat(extension): support tab lock/unlock messaging and status broadcast - Implement background message handlers for lockTab and unlockTab requests - Include current tab locks and open tabs in status payload sent to popup - Provide getOpenTabs function querying chrome.tabs in current window with lock info - Broadcast status messages after lock state changes for UI synchronization docs(readme): update references from real-browser-mcp to browser-controller - Change CLI commands from 'npx real-browser-mcp' to 'npx browser-controller' - Update Cursor MCP install URLs and manual config instructions accordingly - Revise setup commands for Cursor and Claude to use browser-controller - Reflect new agent naming with --agent argument and environment variable test(daemon): add tests for heartbeat eviction and kill endpoint - Simulate clients missing pong responses to verify eviction after timeout - Test replacing clients with same agent name to avoid accumulation - Verify /kill endpoint forcibly disconnects targeted session - Ensure heartbeat functionality cleans up dead connections correctly
…ants - Documented Browser Controller v2.1 components and process model - Described thin client, daemon, bridge, and extension roles in detail - Listed key architecture invariants to prevent regressions - Explained state locations and service worker restart implications - Defined extension points for adding tools and transport policies - Included testing coverage and approach summary fix(background): correct console/network buffers documentation - Updated comment to clarify buffers are in-memory only and lost on SW recycle - Removed incorrect claim of persistence to chrome.storage.session fix(background): handle thrown errors in ws.onmessage with error response - Added try-catch around message handler to catch errors - Sends explicit error response with message id to avoid daemon hanging refactor(background): use first-class sessionId field on WS messages - Removed injecting sessionId into params in favor of top-level field - Adjusted message routing to extract sessionId from top-level field - Removed legacy wire-name aliases to prevent tool name drift fix(daemon): cancel non-idempotent in-flight calls on eviction - Implemented per-call AbortController for daemon to abort ongoing calls - Aborted pending bridge promises when IPC socket closes or is replaced - Added tests to ensure aborted calls do not continue after eviction test: add static drift-guard test for tool name consistency - Ensures tool call names match ToolDefinition.name to prevent retry issues - Catches future discrepancies between tool registry and calls chore(changelog): add 2.1.0 architecture hardening release notes - Summarized critical correctness bugs fixed and major changes - Included minor fixes and test coverage improvements docs(memory): add Ralph memory document capturing key architecture lessons - Detailed past issues, their fixes, and architectural laws for future reference
- Add stable agentName usage for tab locks to prevent orphaned locks on disconnect - Implement releaseByOwner() to free tabs locked by disconnected agents automatically - Update dispatch to accept agentName for consistent lock tracking - Enhance navigation tool to wait for page load + 500ms SPA render delay before snapshot - Return page snapshot inline with navigation result to save separate snapshot calls - Add retry scrollIntoView with 200ms delay to improve click reliability on lazy-rendered elements - Tighten text matching logic in smart-selector to avoid false positives on similar labels - Export isPreciseTextMatch for consistent and testable matching rules - Fix memory leak in tab concurrency queue by removing settled chains from map - Extend popup tab lock message to support agentName for better lock ownership tracking
- Delete .graphify_analysis.json containing previous graph metrics and communities - Remove .graphify_labels.json and its signature file - Clean up generated root and semantic marker files - Remove GRAPH_REPORT.md documentation of the graph structure - Clear obsolete graph data to prepare for fresh graph generation and analysis
- Add lang="en" attribute to html tag for accessibility - Define design tokens with semantic color variables for dark theme - Refactor and expand CSS rules for controls, fields, and layout using CSS variables - Update font families, sizes, weights and spacing for better readability - Enhance connection status dots with smoother animations and color variables - Improve form input styles with focus states, placeholders, and transitions - Revise lists, tabs, and agent rows for consistent spacing and hover effects - Style icon buttons with hover and focus styles using accent colors - Redesign primary button with improved states and animations - Add styled activity log with monospace font and semantic colors - Implement custom thin dark scrollbars for better UI integration - Add bottom-left resize handle with hover and active state transitions - Include prefers-reduced-motion media query to minimize animations - Update html structure with label for attributes for inputs - Adjust fixed sizes and margins for better layout consistency - Change some colors from fixed codes to semantic variables for maintainability
- Define a 4pt-base semantic spacing scale using CSS variables (--space-xs to --space-xl) - Replace all fixed pixel margin, padding, gap, and border-radius values with these variables - Improve layout consistency and maintainability by unifying spacing rules - Expand icon button touch target area using ::before pseudo element and spacing variables - Adjust scrollbar thumb border-radius to use semantic spacing variable - Update resize handle size to use semantic spacing variable instead of fixed pixels
…wser-controller) - README: title real-browser-mcp → Browser Controller - README: remove ofershap CI/npm/personal badges, add noiemany author - README: fix STATE_DIR refs (~/.real-browser-mcp → ~/.browser-controller) - README: fix clone URLs → compnew2006/browser-controller - README: Cursor deeplink → browser-controller config - PRIVACY/CONTRIBUTING/CHROME_WEB_STORE/SECURITY: repo URLs → compnew2006 - .serena memory: update stale repo note
…ed, no config) The pre-push hook runs `npm run lint` which calls eslint — but eslint was never declared as a dependency and there is no eslint config. Same for prettier. Removing the scripts that can't run; typecheck + the 123-test vitest suite are the real quality gates and they pass.
Bumps the all-actions group with 2 updates: [actions/setup-node](https://github.com/actions/setup-node) and [ossf/scorecard-action](https://github.com/ossf/scorecard-action). Updates `actions/setup-node` from 6 to 7 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v6...v7) Updates `ossf/scorecard-action` from 2.4.3 to 2.4.4 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@v2.4.3...v2.4.4) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-actions ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
deleted the
dependabot/github_actions/all-actions-61cd424959
branch
July 25, 2026 20:55
| const handler = handlers[tool]; | ||
| if (!handler) throw new Error(`Unknown tool: ${tool}`); | ||
| return handler(params); | ||
| return handler(params, sessionId, agentName); |
|
|
||
| if (delay) { | ||
| await new Promise(r => setTimeout(r, Math.min(delay, 30000))); | ||
| await new Promise((r) => setTimeout(r, Math.min(delay, 30000))); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the all-actions group with 2 updates: actions/setup-node and ossf/scorecard-action.
Updates
actions/setup-nodefrom 6 to 7Release notes
Sourced from actions/setup-node's releases.
... (truncated)
Commits
8207627Migrate to ESM and upgrade dependencies (#1574)04be95cAdd cache-primary-key and cache-matched-key as outputs (#1577)7c2c68ddocs: Update caching recommendations to mitigate cache poisoning risks (#1567)6a61c03Merge pull request #1569 from jasongin/update-actions-cache-5.1.030eb73bResolve high-severity audit issues4e1a87aUpdate dist360237fStrict equality4f8aac5Bump@actions/cacheto 5.1.0, log cache write deniedf4a67bbOnly usemirrorTokeningetManifestif it's provided (#1548)0355742Remove dummy NODE_AUTH_TOKEN export (#1558)Updates
ossf/scorecard-actionfrom 2.4.3 to 2.4.4Release notes
Sourced from ossf/scorecard-action's releases.
Commits
2d11466Bump action tag for v2.4.4 release (#1688)1bd3285🌱 Bump the docker-images group across 1 directory with 2 updates (#1...913edce🌱 Bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#1671)0957b8f🌱 Bump golang.org/x/net from 0.56.0 to 0.57.0 (#1680)f0061eb🌱 Bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#1687)20ee732🌱 Bump github.com/sigstore/cosign/v2 from 2.6.3 to 2.6.4 (#1685)9f295ef🌱 Bump the github-actions group with 6 updates (#1686)69bf556🌱 Bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.0 (#1681)94e8b96🌱 Bump github.com/sigstore/rekor from 1.5.0 to 1.5.2 (#1673)c7a1b37🌱 Bump github.com/sigstore/fulcio from 1.8.5 to 1.8.6 (#1675)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions