diff --git a/README.md b/README.md index bfc2508..68ae58e 100644 --- a/README.md +++ b/README.md @@ -101,6 +101,18 @@ Clients connect in the simplest shape they support: and manages its own workers. - **Portable Markdown/JSON handoff** when live remote MCP is unavailable. +The dashboard provides native setup commands for OpenCode, Gemini CLI, and +Copilot CLI, a portable plugin for OpenClaw, and a ready-to-copy Eve connection. +Hermes can connect through its native remote MCP and OAuth support. Choose your +tool, approve its access, and keep working in the environment you already use. + +Compatibility is reviewed against dated upstream releases. See the +[portable agent guide](docs/PORTABLE-AGENT-COMPATIBILITY.md), +[Eve setup](docs/EVE-COMPATIBILITY.md), and +[Hermes guide](docs/HERMES-HANDS-OFF.md) for verified setup details and testing +limits. Existing connections keep working; a naming update does not require +reconnecting your Project. + No provider becomes a required dependency. See the [compatibility guide](docs/MCP-COMPATIBILITY.md) for the current protocol and dated client evidence. diff --git a/apps/web/src/App.tsx b/apps/web/src/App.tsx index 75614d9..6d61dcf 100644 --- a/apps/web/src/App.tsx +++ b/apps/web/src/App.tsx @@ -1245,11 +1245,11 @@ function AgentConnectionsPanel({ <>
- Eve 0.29 + Eve

Add a user-scoped connection

- agent/connections/owd.ts + agent/connections/mdevolved.ts
{ it("creates Eve's user-scoped connection module", () => { const source = createEveConnectionSource(MCP_URL); - expect(source).toContain(`const owdMcpUrl = "${MCP_URL}";`); - expect(source).toContain('connector: "oauth/owd"'); + expect(source).toContain('connector: "oauth/mdevolved"'); + expect(source).toContain(`const mdevolvedMcpUrl = "${MCP_URL}";`); + expect(source).toContain("resources: [mdevolvedMcpUrl]"); + expect(source).not.toContain('connector: "oauth/owd"'); expect(source).toContain('principalType: "user"'); expect(source).toContain('"vault.read"'); - expect(source).toContain("resources: [owdMcpUrl]"); expect(source).toContain("autoProvision: true"); expect(source).not.toContain('principalType: "app"'); expect(source).not.toContain("Bearer "); diff --git a/apps/worker/test/agent-access.test.ts b/apps/worker/test/agent-access.test.ts index ab94f54..d356e98 100644 --- a/apps/worker/test/agent-access.test.ts +++ b/apps/worker/test/agent-access.test.ts @@ -1908,9 +1908,9 @@ describe("scoped universal agent access", () => { format: "owd-client-profile-v1", id: "eve", source: { - commit: "d004e6d47e9d25d0380c24b5a47b65a18f8b2784", - connectVersion: "2.0.4", - eveVersion: "0.63.0", + commit: "7bcc0d16e3f41d44fadfd06b5bac3515a82d441d", + connectVersion: "2.3.2", + eveVersion: "0.65.0", repository: "https://github.com/vercel/eve", }, }); diff --git a/compatibility/upstreams.json b/compatibility/upstreams.json index 1590b15..d19451d 100644 --- a/compatibility/upstreams.json +++ b/compatibility/upstreams.json @@ -52,16 +52,16 @@ "source": { "kind": "github-release", "repository": "vercel/eve", - "releaseTag": "eve@0.63.0", - "commit": "d004e6d47e9d25d0380c24b5a47b65a18f8b2784", - "reviewedAt": "2026-09-21" + "releaseTag": "eve@0.65.0", + "commit": "7bcc0d16e3f41d44fadfd06b5bac3515a82d441d", + "reviewedAt": "2026-09-24" }, "dependencies": [ { "kind": "npm", "package": "@vercel/connect", - "version": "2.0.4", - "integrity": "sha512-VD0dY28Nr8uTa5yOWeHQwgn6e3Oj0gbDvkJ3EowPRSJriarPPX5I2oG6IpEg3sFz6t16AY5Us5eHRb0UMkdfVQ==" + "version": "2.3.2", + "integrity": "sha512-qNRdUI6h2zbTruYU92leapFvBRjwF70gewwuj0rBPBHyu2Bnfzm//k4Sc8kA8e/zQfwKbdpYVk8oWe3fNqImzA==" } ], "criticalPaths": [ @@ -80,18 +80,18 @@ { "path": "packages/client-packs/src/eve.ts", "requiredMarkers": [ - "commit: \"d004e6d47e9d25d0380c24b5a47b65a18f8b2784\"", - "connectVersion: \"2.0.4\"", - "eveVersion: \"0.63.0\"", - "reviewedAt: \"2026-09-21\"" + "commit: \"7bcc0d16e3f41d44fadfd06b5bac3515a82d441d\"", + "connectVersion: \"2.3.2\"", + "eveVersion: \"0.65.0\"", + "reviewedAt: \"2026-09-24\"" ] }, { "path": "docs/EVE-COMPATIBILITY.md", "requiredMarkers": [ - "`0.63.0`", - "`d004e6d47e9d25d0380c24b5a47b65a18f8b2784`", - "`2.0.4`" + "`0.65.0`", + "`7bcc0d16e3f41d44fadfd06b5bac3515a82d441d`", + "`2.3.2`" ] } ] @@ -153,9 +153,9 @@ "source": { "kind": "github-release", "repository": "NousResearch/hermes-agent", - "releaseTag": "v2026.9.21", - "commit": "d337b736aa1e8ebecfab043842d13e4a2d2f48a3", - "reviewedAt": "2026-09-21" + "releaseTag": "v2026.9.24", + "commit": "f97608f178d1ffeca59860195ab7da295f7c8e5f", + "reviewedAt": "2026-09-24" }, "criticalPaths": [ "pyproject.toml", @@ -174,9 +174,9 @@ { "path": "docs/HERMES-HANDS-OFF.md", "requiredMarkers": [ - "`0.21.4`", - "`d337b736aa1e8ebecfab043842d13e4a2d2f48a3`", - "Reviewed `2026-09-21`" + "`0.21.5`", + "`f97608f178d1ffeca59860195ab7da295f7c8e5f`", + "Reviewed `2026-09-24`" ] } ] diff --git a/docs/EVE-COMPATIBILITY.md b/docs/EVE-COMPATIBILITY.md index af019bc..1305d80 100644 --- a/docs/EVE-COMPATIBILITY.md +++ b/docs/EVE-COMPATIBILITY.md @@ -10,24 +10,30 @@ The reviewed profile is pinned to: | Contract | Reviewed value | | ----------------- | ------------------------------------------ | -| Eve | `0.63.0` | -| Eve source commit | `d004e6d47e9d25d0380c24b5a47b65a18f8b2784` | -| `@vercel/connect` | `2.0.4` | +| Eve | `0.65.0` | +| Eve source commit | `7bcc0d16e3f41d44fadfd06b5bac3515a82d441d` | +| `@vercel/connect` | `2.3.2` | | License | Apache-2.0 | -| Reviewed | September 21, 2026 | +| Reviewed | September 24, 2026 | This is a source-verified compatibility profile. It does not yet claim that a live Eve deployment has completed MDevolved's independent two-agent acceptance run. Unknown future Eve connection or identity changes fall back to MDevolved's universal MCP setup until the profile is reviewed again. -Eve 0.63.0 retains authored `agent/connections/*.ts` modules, +Eve 0.65.0 retains authored `agent/connections/*.ts` modules, `defineMcpClientConnection`, and the user-scoped `@vercel/connect/eve` -`connect()` helper used by MDevolved. Version `2.0.4` is the newest reviewed -helper old enough to satisfy the repository's minimum-release-age policy; -newer releases remain monitor-visible drift. The Eve update changes background -tool and runtime behavior but leaves this user-scoped remote connection shape -intact; the exact generated module type-checks against both current packages. +`connect()` helper used by MDevolved. The connection definitions, runtime, and +connection documentation have identical Git blob identities between the +previous `0.63.0` pin and this release. Connect `2.3.2` retains explicit user +principals, scopes/resources, and opt-in connector provisioning; its token-cache +eviction does not replace MDevolved's authoritative grant checks. The exact +generated module type-checks against both pinned packages. + +The newer Eve `0.66.2` release was observed during this review but is not the +installed compatibility target; the monitor deliberately continues to report +that drift. MDevolved supports `server/discover`, so the connection keeps Eve's +default protocol discovery rather than forcing the legacy handshake. Until MDevolved is accepted into Eve's registry, use the dashboard-generated module rather than claiming an `eve add` package that does not exist. @@ -53,7 +59,11 @@ and qualifies them with its connection name. ## Install the connection -Create `agent/connections/owd.ts`: +Create `agent/connections/mdevolved.ts`: + +Keep an existing `owd.ts` connection working as-is; do not add a duplicate, +rename its connector, or repeat authorization just for the naming update. +The canonical name below is for new connections. ```ts import { connect } from "@vercel/connect/eve"; diff --git a/docs/HERMES-HANDS-OFF.md b/docs/HERMES-HANDS-OFF.md index 238f9fa..e4f2c7d 100644 --- a/docs/HERMES-HANDS-OFF.md +++ b/docs/HERMES-HANDS-OFF.md @@ -4,8 +4,8 @@ **Status:** inert, script-free guidance over the generic MDevolved MCP services -**Source-verified profile:** Hermes Agent `0.21.4`, tag `v2026.9.21`, commit -`d337b736aa1e8ebecfab043842d13e4a2d2f48a3`. Reviewed `2026-09-21`. +**Source-verified profile:** Hermes Agent `0.21.5`, tag `v2026.9.24`, commit +`f97608f178d1ffeca59860195ab7da295f7c8e5f`. Reviewed `2026-09-24`. Hermes now has native remote MCP OAuth support. Point that client at `https://YOUR-MDEVOLVED-HOST/mcp`; do not add a transport bridge or place OAuth @@ -17,6 +17,12 @@ OAuth with an explicit headless login path, and fenced delegated-child identity. Hermes memory and skill state remain runtime-owned and are never ingested as MDevolved authority or raw session history. +The September 24 tagged-source review found no changes to `tools/mcp_tool.py`, +`tools/mcp_oauth.py`, or `tools/mcp_oauth_manager.py` from the previous pin. +The CLI now shares its MCP enabled-state helper; the remote URL/OAuth setup +remains unchanged. Device login is an explicit Hermes action, not authority +that this adapter can create. + The same guidance is discoverable as the MCP resource `mdevolved://adapters/hermes/hands-off/v1`. diff --git a/docs/PORTABLE-AGENT-COMPATIBILITY.md b/docs/PORTABLE-AGENT-COMPATIBILITY.md index 32b3044..fc9866c 100644 --- a/docs/PORTABLE-AGENT-COMPATIBILITY.md +++ b/docs/PORTABLE-AGENT-COMPATIBILITY.md @@ -1,25 +1,32 @@ # Portable agent compatibility -This receipt records the exact upstream surfaces reviewed for PAC1 on -2026-09-21. These are compatibility claims, not vendor endorsements or claims +This receipt records the exact upstream surfaces reviewed for PAC1, refreshed on +2026-09-24. These are compatibility claims, not vendor endorsements or claims that MDevolved controls a client's runtime. | Client or standard | Reviewed release | Source contract used by MDevolved | | ------------------ | --------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Agent Plugins | `1.0.0` | Root `plugin.json`, optional root `mcp.json`, immediate-child `skills/*/SKILL.md`, and `streamable-http`; OAuth remains client-managed. | | OpenCode | `v1.18.32` at `545f51d26cc39a907d2867492d498d9607ea5fa4` | `opencode mcp add mdevolved --url ` creates a remote server; OpenCode owns its OAuth flow and credentials. | -| OpenClaw | `v2026.9.5` at `ec9c1a13db8938e5a3eaa51fca2e981cde2395a9` | Local archives with root Agent Plugins metadata are installed through `openclaw plugins install`; supported skill and HTTP MCP components are mapped into OpenClaw. | -| Gemini CLI | `v0.60.0` at `733edcb597ce690ac2e2fe3b3b3690b60a4c8f27` | `gemini mcp add mdevolved --transport http` adds the remote MCP server. | -| GitHub Copilot CLI | `v1.0.87` at `d418dbf1061152afa17500cbc69478f8dce153d8` | `copilot mcp add --transport http mdevolved ` adds the remote MCP server; Copilot owns its interactive authorization state. | +| OpenClaw | `v2026.9.6` at `eb377ac59e6c9fd6c7705028034812becf00271b` | Local archives with root Agent Plugins metadata are installed through `openclaw plugins install`; supported skill and HTTP MCP components are mapped into OpenClaw. | +| Gemini CLI | `v0.61.0` at `bb523741c7429a44d03e964bc124c7c92df59d5f` | `gemini mcp add mdevolved --transport http` adds the remote MCP server. | +| GitHub Copilot CLI | `v1.0.88` at `c13b3dcae4f1e176c5a074c0d063a6e9f258081f` | `copilot mcp add --transport http mdevolved ` adds the remote MCP server; Copilot owns its interactive authorization state. | Primary sources: - [Agent Plugins 1.0 specification](https://agent-plugins.org/specification) - [OpenCode MCP command source](https://github.com/anomalyco/opencode/blob/v1.18.32/packages/opencode/src/cli/cmd/mcp.ts) -- [OpenClaw bundle contract](https://github.com/openclaw/openclaw/blob/v2026.9.5/docs/plugins/bundles.md) -- [Gemini CLI command reference](https://github.com/google-gemini/gemini-cli/blob/v0.60.0/docs/cli/cli-reference.md) +- [OpenClaw bundle contract](https://github.com/openclaw/openclaw/blob/v2026.9.6/docs/plugins/bundles.md) +- [Gemini CLI command reference](https://github.com/google-gemini/gemini-cli/blob/v0.61.0/docs/cli/cli-reference.md) - [GitHub Copilot CLI command reference](https://docs.github.com/en/copilot/reference/copilot-cli-reference/cli-command-reference) +The refreshed Gemini MCP-add implementation and OpenClaw bundle documentation +are unchanged from the previous pins. OpenCode's reviewed release is still +current. [Copilot 1.0.88 release notes](https://github.com/github/copilot-cli/releases/tag/v1.0.88) +describe MCP reconnect, OAuth, and tool-cache fixes; its proprietary +implementation was not inspected. No generated setup command or archive layout +needed changing. These checks do not certify a live install or OAuth session. + ## Boundary The dashboard emits only a public deployment URL. The generated Agent Plugins diff --git a/docs/RELEASE-COMPATIBILITY.md b/docs/RELEASE-COMPATIBILITY.md index b0c662c..42974e6 100644 --- a/docs/RELEASE-COMPATIBILITY.md +++ b/docs/RELEASE-COMPATIBILITY.md @@ -16,9 +16,9 @@ existing `owd-sync` installations remain the supported compatibility path. | MCP | Authenticated Streamable HTTP against MCP `2026-07-28`, with stateless `2025-11-25` compatibility | Read-only vault tools are the portable baseline. Project behavior uses ordinary MCP Tools, Resources, and Prompts. See [MCP compatibility](MCP-COMPATIBILITY.md). | | Project lifecycle | `open_project`, `wait_for_project_connection`, and `mdevolved_resume`; lower-level `resume_project` remains compatible | Create, join, rejoin, and resume converge on one exact Project without a client-specific transport. | | Obsidian Mind profile | `8.4.0` at commit `af615d100a1d04561409ab9a1e71e615efa1d87b` | MDevolved runs beside `qmd`/`om`, preserves native layout, and never turns local profile data into authority. | -| Eve.dev profile | Eve `0.63.0` at commit `d004e6d47e9d25d0380c24b5a47b65a18f8b2784`; `@vercel/connect` `2.0.4` | Uses Eve's native user-scoped MCP connection. Separate attribution requires a distinct connector identity. | +| Eve.dev profile | Eve `0.65.0` at commit `7bcc0d16e3f41d44fadfd06b5bac3515a82d441d`; `@vercel/connect` `2.3.2` | Uses Eve's native user-scoped MCP connection. Separate attribution requires a distinct connector identity. | | Albatross profile | Albatross `2.5.0` at commit `e458e4277f463a4688f127ea6ea61f5a344b64b8`; `mcp-remote` `0.14.3` | Uses a pinned stdio bridge while MDevolved remains standard remote Streamable HTTP MCP with OAuth. | -| Hermes hands-off adapter | Hermes `0.21.4` at commit `d337b736aa1e8ebecfab043842d13e4a2d2f48a3` | Uses Hermes's native remote MCP/OAuth client; MDevolved stores bounded evidence and never becomes its scheduler or runtime. | +| Hermes hands-off adapter | Hermes `0.21.5` at commit `f97608f178d1ffeca59860195ab7da295f7c8e5f` | Uses Hermes's native remote MCP/OAuth client; MDevolved stores bounded evidence and never becomes its scheduler or runtime. | | LangChain recipe | LangChain `1.4.2` at commit `a18de590e7ccf5c647fbf3d689e5f1a15f78e9f5`; built-in `langchain.mcp` beta | Uses `MCPAdapter` over FastMCP OAuth. Tools are the baseline; Prompts and Resources remain available through the underlying FastMCP client. | | Portable backup | New writes use `mdevolved-backup-v1`; `owd-backup-v1` remains readable | Unknown or malformed formats fail before staging; credentials and live grants never restore. | | Workspace snapshot | New writes use `mdevolved-snapshot-v3`; `owd-snapshot-v2` remains readable | Unknown required capabilities fail before staging. Credentials and live grants never restore. | diff --git a/docs/UPDATE-PASS-2026-09-24.md b/docs/UPDATE-PASS-2026-09-24.md new file mode 100644 index 0000000..c473eb0 --- /dev/null +++ b/docs/UPDATE-PASS-2026-09-24.md @@ -0,0 +1,70 @@ +# September 24 compatibility update + +## Outcome + +Local update candidate for the existing agent integrations. No schema, migration, +sync protocol, authorization, setup command, or plugin archive layout changed. + +- Eve's installed compatibility target advances from `0.63.0` to `0.65.0`, + with `@vercel/connect` from `2.0.4` to `2.3.2`. The generated connection + fixture, exposed profile, release checks, and documentation advance together. +- Tagged-source reviews advance Hermes to `0.21.5` / `v2026.9.24`, OpenClaw to + `v2026.9.6`, and Gemini CLI to `v0.61.0`. +- Copilot CLI's release/documentation review advances to `v1.0.88`; its + implementation is proprietary, and no live certification is claimed. +- OpenCode, Obsidian Mind, Albatross, mcp-remote, and LangChain still match + their existing reviewed releases. +- Corrected the Eve dashboard and documentation to use the existing canonical + generator and `mdevolved.ts` filename for new connections. Existing `owd` + connections remain supported and must not be duplicated or re-authorized. + +The GitHub comparison endpoint truncated Eve's changed-file list at 300 files. +The review therefore compared complete recursive Git trees: connection +definitions, runtime, and documentation retain identical blob identities +between the old pin and the selected release. Connect's published implementation +retains explicit user principals, token scopes/resources, and opt-in connector +provisioning. The source references are in the individual compatibility docs. + +## Validation + +- Focused Vitest: **103/103**, covering client profiles, native setup commands, + inert plugin archives, and MCP access/authorization behavior. +- Focused Playwright: **2/2**, exercising agent setup including canonical Eve + output on desktop and narrow viewports after the review repair. +- `pnpm typecheck`, `pnpm upstream:config:check`, `pnpm release:check`, + `pnpm lint`, and `pnpm build:web`: passed. +- Changed-file formatting and `git diff --check`: passed. +- `pnpm audit --json`: zero known vulnerabilities after installation. +- GitHub: no open Dependabot security alerts; the latest CI, desktop/CLI, + and compatibility-monitor runs inspected were successful. + +The full repository/browser/deployment gate was not repeated for this local +profile update. A release still requires the repository's applicable release +gate. No real client OAuth sessions or paid model runs were exercised. + +An independent upstream source audit supported the selected client pins. The +final diff critic identified a real mismatch: the dashboard still generated +legacy Eve connection names while the docs described canonical names. Rework +reused the existing canonical generator, corrected the displayed filename, +removed the stale version badge, and added desktop/narrow browser assertions. +The legacy generator and its compatibility fixtures remain supported. + +## Deferred updates and delivery + +Eve `0.66.2` was observed but is not the installed target of this pass; the +upstream monitor intentionally continues to report that release drift. +Newer framework/toolchain packages and the pinned YAOS/Yjs synchronization stack +remain separate upgrade work. No known security advisory requires their +immediate replacement. Existing Dependabot PRs #26, #29, and #71 remain open +and were not changed or merged. + +The owner subsequently authorized commit, GitHub delivery, README updates, and +deployment. The README now describes the available setup paths and links to +dated compatibility evidence without claiming live certification. Release +delivery requires the complete gate on the candidate commit, successful PR CI, +and health verification of the existing production Worker. The PR and task +delivery receipt record the resulting commit and deployment identifiers. + +No schema migration, npm publication, new cloud resource, or paid service is +required. Existing alpha deployments retain their original resource identities +through `wrangler.legacy.jsonc`; rollback uses the preceding Worker version. diff --git a/e2e/phase8-foundation.spec.ts b/e2e/phase8-foundation.spec.ts index 6ba6af4..6957bda 100644 --- a/e2e/phase8-foundation.spec.ts +++ b/e2e/phase8-foundation.spec.ts @@ -1853,6 +1853,12 @@ test("shows one compact agent setup path at a time", async ({ browser }) => { ); } + await agents.getByRole("button", { name: "Eve", exact: true }).click(); + const eveGuide = agents.locator(".agent-client-guide"); + await expect(eveGuide).toContainText("agent/connections/mdevolved.ts"); + await expect(eveGuide).toContainText('connector: "oauth/mdevolved"'); + await expect(eveGuide).not.toContainText('connector: "oauth/owd"'); + await agents.getByRole("button", { name: "OpenClaw" }).click(); await expect( agents.getByRole("heading", { name: "Install one portable plugin" }), diff --git a/packages/client-packs/owd-eve/SKILL.md b/packages/client-packs/owd-eve/SKILL.md index 3e65e83..143cf5d 100644 --- a/packages/client-packs/owd-eve/SKILL.md +++ b/packages/client-packs/owd-eve/SKILL.md @@ -31,7 +31,7 @@ client-side Project authority, or a second MDevolved endpoint. Do not pin a loca tool allowlist: MDevolved's advertised catalog and server-side grant remain authoritative. -Eve `0.63.0` can install integrations from its registry with `eve add` or +Eve `0.65.0` can install integrations from its registry with `eve add` or interactive `/add`. MDevolved is not represented as registry-installed until Eve's upstream registry accepts it. Until then, use the generated `agent/connections/owd.ts` module from the MDevolved dashboard; do not claim that diff --git a/packages/client-packs/package.json b/packages/client-packs/package.json index 51a2671..69bd319 100644 --- a/packages/client-packs/package.json +++ b/packages/client-packs/package.json @@ -15,7 +15,7 @@ "./owd-obsidian-mind": "./owd-obsidian-mind/SKILL.md" }, "devDependencies": { - "@vercel/connect": "2.0.4", - "eve": "0.63.0" + "@vercel/connect": "2.3.2", + "eve": "0.65.0" } } diff --git a/packages/client-packs/src/eve.ts b/packages/client-packs/src/eve.ts index 7367aca..221bb17 100644 --- a/packages/client-packs/src/eve.ts +++ b/packages/client-packs/src/eve.ts @@ -103,12 +103,12 @@ export const EVE_COMPATIBILITY_PROFILE = { "Top-level schedules run as an app/runtime principal and cannot silently borrow a user's MDevolved grant. Dispatch scheduled MDevolved work through a user-authenticated route or require an explicit user action; do not downgrade MDevolved to app-scoped authorization.", }, source: { - commit: "d004e6d47e9d25d0380c24b5a47b65a18f8b2784", - connectVersion: "2.0.4", - eveVersion: "0.63.0", + commit: "7bcc0d16e3f41d44fadfd06b5bac3515a82d441d", + connectVersion: "2.3.2", + eveVersion: "0.65.0", license: "Apache-2.0", repository: "https://github.com/vercel/eve", - reviewedAt: "2026-09-21", + reviewedAt: "2026-09-24", }, } as const satisfies OwdEveCompatibilityProfile; diff --git a/packages/client-packs/test/eve.test.ts b/packages/client-packs/test/eve.test.ts index d21e158..74225e1 100644 --- a/packages/client-packs/test/eve.test.ts +++ b/packages/client-packs/test/eve.test.ts @@ -31,12 +31,12 @@ describe("Eve compatibility profile", () => { format: "owd-client-profile-v1", id: "eve", source: { - commit: "d004e6d47e9d25d0380c24b5a47b65a18f8b2784", - connectVersion: "2.0.4", - eveVersion: "0.63.0", + commit: "7bcc0d16e3f41d44fadfd06b5bac3515a82d441d", + connectVersion: "2.3.2", + eveVersion: "0.65.0", license: "Apache-2.0", repository: "https://github.com/vercel/eve", - reviewedAt: "2026-09-21", + reviewedAt: "2026-09-24", }, }); expect(JSON.parse(serializeEveCompatibilityProfile())).toStrictEqual( diff --git a/packages/client-packs/test/fixtures/eve-0.63.0-connection.ts b/packages/client-packs/test/fixtures/eve-0.65.0-connection.ts similarity index 100% rename from packages/client-packs/test/fixtures/eve-0.63.0-connection.ts rename to packages/client-packs/test/fixtures/eve-0.65.0-connection.ts diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index dbca8da..00b9371 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -167,11 +167,11 @@ importers: packages/client-packs: devDependencies: '@vercel/connect': - specifier: 2.0.4 - version: 2.0.4(ai@7.0.107(zod@4.4.3))(eve@0.63.0(ai@7.0.107(zod@4.4.3))) + specifier: 2.3.2 + version: 2.3.2(@modelcontextprotocol/sdk@1.30.0(@cfworker/json-schema@4.1.1)(supports-color@10.2.2)(zod@4.4.3))(ai@7.0.107(zod@4.4.3))(eve@0.65.0(ai@7.0.107(zod@4.4.3))) eve: - specifier: 0.63.0 - version: 0.63.0(ai@7.0.107(zod@4.4.3)) + specifier: 0.65.0 + version: 0.65.0(ai@7.0.107(zod@4.4.3)) packages/contracts: dependencies: @@ -1645,22 +1645,23 @@ packages: cpu: [x64] os: [win32] - '@vercel/cli-config@0.2.6': - resolution: {integrity: sha512-2AsKCf6gE/Eniq09ARm1RK9rQMV5pcAHU7BFcR9MISO+4/RsjjkaYbQN6G85/xi9pYZ5CJNXvYn4TI6p1jKBcg==} + '@vercel/cli-config@0.3.0': + resolution: {integrity: sha512-kQLt5Pm8wKd7/imzDY9/9u0tf8OuRkAuXI+s7j057FSUrXapAmumJSKwDqnR4ZZqdWoUcNLlFAgVIAdiwcGTcw==} '@vercel/cli-exec@1.0.1': resolution: {integrity: sha512-g9XerViJ/paZujufXYcu5XYI2vU2rtB4sgdpjUHde5RnOkdmpu0ngH46LCFGHoPXO/C+qDPSczIHIRN+8Q2YKQ==} engines: {node: '>= 18'} - '@vercel/connect@2.0.4': - resolution: {integrity: sha512-VD0dY28Nr8uTa5yOWeHQwgn6e3Oj0gbDvkJ3EowPRSJriarPPX5I2oG6IpEg3sFz6t16AY5Us5eHRb0UMkdfVQ==} + '@vercel/connect@2.3.2': + resolution: {integrity: sha512-qNRdUI6h2zbTruYU92leapFvBRjwF70gewwuj0rBPBHyu2Bnfzm//k4Sc8kA8e/zQfwKbdpYVk8oWe3fNqImzA==} peerDependencies: '@ai-sdk/mcp': ^1 || ^2 '@auth/core': '>=0.37.0' '@chat-adapter/slack': ^4.0.0 + '@modelcontextprotocol/sdk': ^1.29.0 ai: ^6 || ^7.0.0-beta.0 better-auth: '>=1.5.0' - eve: '>=0.13.7' + eve: '>=0.39.1' peerDependenciesMeta: '@ai-sdk/mcp': optional: true @@ -1668,6 +1669,8 @@ packages: optional: true '@chat-adapter/slack': optional: true + '@modelcontextprotocol/sdk': + optional: true ai: optional: true better-auth: @@ -1679,8 +1682,8 @@ packages: resolution: {integrity: sha512-UycprH3T6n3jH0k44NHMa7pnFHGu/N05MjojYr+Mc6I7obkoLIJujSWwin1pCvdy/eOxrI/l3uDLQsmcrOb4ug==} engines: {node: '>= 20'} - '@vercel/oidc@3.8.7': - resolution: {integrity: sha512-fRu59npOu+1vsV570tiLKskfuRyOJ1MqceAkXbTIfWPnM+c9ve1tSK81oj4umKKirymlGUss3V60Lm5I38rKDw==} + '@vercel/oidc@3.8.9': + resolution: {integrity: sha512-TcbdH3YtGS2KU98T99dN4sbf+E4vbJZsJTRN97wKQ7QWQ0BR7U02QX3KN4+5GHxBtKTj1c5CnvTTitc2ZRad0A==} engines: {node: '>= 20'} '@vitejs/plugin-react@6.0.3': @@ -2030,14 +2033,15 @@ packages: resolution: {integrity: sha512-aIL5Fx7mawVa300al2BnEE4iNvo1qETxLrPI/o05L7z6go7fCw1J6EQmbK4FmJ2AS7kgVF/KEZWufBfdClMcPg==} engines: {node: '>= 0.6'} - eve@0.63.0: - resolution: {integrity: sha512-iDv0S4MXvZimaXNTJnyB2THumRQLWQSAgpMcZsGtMNquYQpSKB1+i8sxX4KJOHHCLd04lwD+06xnh+ja7rlZIw==} + eve@0.65.0: + resolution: {integrity: sha512-16dcyvpucnMp6f1TKZROvRrDAYWIlV7ulZfEMK+IuK1AVXMQPoLLOrGuLT/qI1TjIkxZt9g1JcXXOv/uu3yjdQ==} engines: {node: '>=24'} hasBin: true peerDependencies: '@opentelemetry/api': ^1.0.0 ai: ^7.0.105 braintrust: ^3.0.0 + chat: ^4.41.0 dd-trace: ^6.13.0 just-bash: ^3.1.0 microsandbox: ^0.5.0 @@ -2046,6 +2050,8 @@ packages: optional: true braintrust: optional: true + chat: + optional: true dd-trace: optional: true just-bash: @@ -4166,7 +4172,7 @@ snapshots: '@typescript/typescript-win32-x64@7.0.2': optional: true - '@vercel/cli-config@0.2.6': + '@vercel/cli-config@0.3.0': dependencies: xdg-app-paths: 5.5.1 zod: 4.1.11 @@ -4175,18 +4181,19 @@ snapshots: dependencies: execa: 5.1.1 - '@vercel/connect@2.0.4(ai@7.0.107(zod@4.4.3))(eve@0.63.0(ai@7.0.107(zod@4.4.3)))': + '@vercel/connect@2.3.2(@modelcontextprotocol/sdk@1.30.0(@cfworker/json-schema@4.1.1)(supports-color@10.2.2)(zod@4.4.3))(ai@7.0.107(zod@4.4.3))(eve@0.65.0(ai@7.0.107(zod@4.4.3)))': dependencies: - '@vercel/oidc': 3.8.7 + '@vercel/oidc': 3.8.9 optionalDependencies: + '@modelcontextprotocol/sdk': 1.30.0(@cfworker/json-schema@4.1.1)(supports-color@10.2.2)(zod@4.4.3) ai: 7.0.107(zod@4.4.3) - eve: 0.63.0(ai@7.0.107(zod@4.4.3)) + eve: 0.65.0(ai@7.0.107(zod@4.4.3)) '@vercel/oidc@3.2.0': {} - '@vercel/oidc@3.8.7': + '@vercel/oidc@3.8.9': dependencies: - '@vercel/cli-config': 0.2.6 + '@vercel/cli-config': 0.3.0 '@vercel/cli-exec': 1.0.1 jose: 5.10.0 @@ -4540,7 +4547,7 @@ snapshots: etag@1.8.1: {} - eve@0.63.0(ai@7.0.107(zod@4.4.3)): + eve@0.65.0(ai@7.0.107(zod@4.4.3)): dependencies: ai: 7.0.107(zod@4.4.3) nitro: 3.0.260903-beta diff --git a/scripts/check-client-profile-fixtures.test.mjs b/scripts/check-client-profile-fixtures.test.mjs index 66e3a13..c8d6294 100644 --- a/scripts/check-client-profile-fixtures.test.mjs +++ b/scripts/check-client-profile-fixtures.test.mjs @@ -9,7 +9,7 @@ const normalizeSource = (source) => source.replace(/\s+/gu, " ").trim(); test("the generated Eve connection matches the pinned type-checked fixture", async () => { const fixture = await readFile( new URL( - "../packages/client-packs/test/fixtures/eve-0.63.0-connection.ts", + "../packages/client-packs/test/fixtures/eve-0.65.0-connection.ts", import.meta.url, ), "utf8", diff --git a/scripts/check-release-contract.mjs b/scripts/check-release-contract.mjs index 0dd5178..e4f8d48 100644 --- a/scripts/check-release-contract.mjs +++ b/scripts/check-release-contract.mjs @@ -116,8 +116,8 @@ if ( !eveCompatibility.includes( "This is a source-verified compatibility profile", ) || - !eveCompatibility.includes("| Eve | `0.63.0`") || - !eveCompatibility.includes("| `@vercel/connect` | `2.0.4`") || + !eveCompatibility.includes("| Eve | `0.65.0`") || + !eveCompatibility.includes("| `@vercel/connect` | `2.3.2`") || !marketingSite.includes('id="eve"') || !normalizedMarketingSite.includes( "Eve runs the agent. MDevolved makes the work portable.", @@ -153,13 +153,13 @@ if ( "`v1.18.32` at `545f51d26cc39a907d2867492d498d9607ea5fa4`", ) || !portableAgentCompatibility.includes( - "`v2026.9.5` at `ec9c1a13db8938e5a3eaa51fca2e981cde2395a9`", + "`v2026.9.6` at `eb377ac59e6c9fd6c7705028034812becf00271b`", ) || !portableAgentCompatibility.includes( - "`v0.60.0` at `733edcb597ce690ac2e2fe3b3b3690b60a4c8f27`", + "`v0.61.0` at `bb523741c7429a44d03e964bc124c7c92df59d5f`", ) || !portableAgentCompatibility.includes( - "`v1.0.87` at `d418dbf1061152afa17500cbc69478f8dce153d8`", + "`v1.0.88` at `c13b3dcae4f1e176c5a074c0d063a6e9f258081f`", ) ) { throw new Error( @@ -167,8 +167,8 @@ if ( ); } if ( - !hermesCompatibility.includes("Hermes Agent `0.21.4`") || - !hermesCompatibility.includes("`d337b736aa1e8ebecfab043842d13e4a2d2f48a3`") || + !hermesCompatibility.includes("Hermes Agent `0.21.5`") || + !hermesCompatibility.includes("`f97608f178d1ffeca59860195ab7da295f7c8e5f`") || !hermesCompatibility.includes("native remote MCP OAuth support") || !normalizedHermesCompatibility.includes( "does not claim vendor certification or a completed live Hermes acceptance run",