Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
54 commits
Select commit Hold shift + click to select a range
d3e81de
fix(completion): a !reference tag anywhere in the file breaks all inp…
X-Guardian Sep 8, 2026
9538d21
chore(deps): bump js-yaml from 4.2.0 to 4.3.2 (#264)
dependabot[bot] Sep 8, 2026
0999324
chore(deps-dev): bump fast-uri from 3.1.5 to 3.1.7 (#265)
dependabot[bot] Sep 8, 2026
ecd1aeb
chore(deps-dev): bump the dev-dependencies group with 9 updates (#266)
dependabot[bot] Sep 8, 2026
574d38d
chore(release): 0.17.0 [skip ci]
github-actions[bot] Sep 8, 2026
cabacbc
chore(deps-dev): bump mocha from 11.8.0 to 12.0.0 (#267)
dependabot[bot] Sep 8, 2026
ea9b26a
chore(release): 0.17.1 [skip ci]
github-actions[bot] Sep 8, 2026
42d310c
fix(parser): tolerate any local YAML tag, not just sequence !referenc…
X-Guardian Sep 8, 2026
aaf85b3
chore(release): 0.17.2 [skip ci]
github-actions[bot] Sep 8, 2026
8bd3ed0
fix(parser): merge YAML merge keys (`<<:`) as GitLab does (#274)
X-Guardian Sep 8, 2026
48e72c1
chore(release): 0.17.3 [skip ci]
github-actions[bot] Sep 8, 2026
dfed502
fix(providers): match cached component templatePath regardless of ref…
Cid-oe Sep 9, 2026
a83832c
chore(release): 0.17.4 [skip ci]
github-actions[bot] Sep 9, 2026
e3cac4f
fix(details): make Refresh Versions work in the browser-opened detail…
X-Guardian Sep 10, 2026
70e144c
chore(release): 0.17.5 [skip ci]
github-actions[bot] Sep 10, 2026
b020d2d
refactor(webview): serve loading-view CSS from linted external file u…
X-Guardian Sep 11, 2026
20bef37
chore(release): 0.17.6 [skip ci]
github-actions[bot] Sep 11, 2026
1688b3a
chore(ci): bump huntridge-labs/argus/.github/workflows/reusable-secur…
dependabot[bot] Sep 15, 2026
fc76bf3
chore(release): 0.17.7 [skip ci]
github-actions[bot] Sep 15, 2026
8dda61e
chore(ci): point Dependabot at beta (#296)
eFAILution Sep 15, 2026
d67019f
chore(release): 0.17.8 [skip ci]
github-actions[bot] Sep 15, 2026
dff64be
chore(deps-dev): bump the dev-dependencies group with 6 updates (#297)
eFAILution Sep 15, 2026
0e5baeb
chore(release): 0.17.9 [skip ci]
github-actions[bot] Sep 15, 2026
324dc3d
fix(webview): restore version switching in the component browser and …
X-Guardian Sep 15, 2026
4ba468a
chore(release): 0.17.10 [skip ci]
github-actions[bot] Sep 15, 2026
8a93745
fix(ai): repair dangling component references in architecture.yaml (#…
eFAILution Sep 15, 2026
7ebd81a
chore(ai): regenerate .ai/index.yaml
eFAILution Sep 15, 2026
a2f4b09
fix(completion): treat boolean inputs as booleans, not quoted strings…
X-Guardian Sep 21, 2026
8f1a991
fix(details): share one message handler across both details-panel ent…
X-Guardian Sep 21, 2026
8b0012e
chore(release): 0.17.11 [skip ci]
github-actions[bot] Sep 21, 2026
b236672
chore(webview): declare asset resource roots and unit-test the CSP he…
X-Guardian Sep 21, 2026
ba079e4
chore(release): 0.17.12 [skip ci]
github-actions[bot] Sep 21, 2026
ae88710
chore(ci): bump argus reusable-security-hardening to 1.12.5 (#306)
eFAILution Sep 21, 2026
32b61e2
chore(deps-dev): bump the dev-dependencies group with 6 updates (#307)
eFAILution Sep 21, 2026
a0a557b
chore(release): 0.17.13 [skip ci]
github-actions[bot] Sep 21, 2026
701c444
refactor(webview): serve the no-sources and error views from linted e…
X-Guardian Sep 23, 2026
59c4841
chore(release): 0.17.14 [skip ci]
github-actions[bot] Sep 23, 2026
5ee46a1
refactor(webview): serve the component details panel from linted exte…
X-Guardian Sep 24, 2026
6eef973
chore(release): 0.17.15 [skip ci]
github-actions[bot] Sep 24, 2026
66ab25b
refactor(webview): serve the Component Browser from linted external a…
X-Guardian Sep 25, 2026
b3ee8e3
chore(release): 0.17.16 [skip ci]
github-actions[bot] Sep 25, 2026
b1f50aa
test(webview): fail the build when a builder emits inline code (#310)
eFAILution Sep 25, 2026
bacbb7b
chore(release): 0.17.17 [skip ci]
github-actions[bot] Sep 25, 2026
7d253a4
fix(browser): make version preferences save (#313)
X-Guardian Sep 29, 2026
1af8a85
chore(ci): bump huntridge-labs/argus/.github/workflows/reusable-secur…
dependabot[bot] Sep 29, 2026
664e3d1
chore(deps-dev): bump fast-uri from 3.1.5 to 3.1.8 (#317)
dependabot[bot] Sep 29, 2026
5939ab5
chore(deps-dev): bump dotenv from 17.4.2 to 18.0.3 (#316)
dependabot[bot] Sep 29, 2026
07a198a
chore(deps-dev): bump the dev-dependencies group with 14 updates (#315)
dependabot[bot] Sep 29, 2026
611e0e6
chore(release): 0.17.18 [skip ci]
github-actions[bot] Sep 29, 2026
b6fab18
refactor(webview): put the Component Browser under a Content-Security…
X-Guardian Oct 2, 2026
81cab30
fix(component): drop the https:// scheme from inserted components (#323)
X-Guardian Oct 2, 2026
6c371f5
chore(release): 0.17.19 [skip ci]
github-actions[bot] Oct 2, 2026
fddb382
docs(readme): modernize the README layout (#335)
eFAILution Oct 2, 2026
4ea5a7f
docs: update AICaC badge to reflect Comprehensive compliance
eFAILution Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 14 additions & 11 deletions .ai/architecture.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,12 +22,12 @@ components:
validationProvider.ts: Input validation with Quick Fixes
componentBrowserProvider.ts: Component browser webview UI
componentDetector.ts: Detect GitLab CI component usage in YAML
componentHtmlRenderer.ts: Render component docs as HTML
hoverContentBuilder.ts: Build the hover popup's markdown body (vscode-free, unit-tested)
depends_on:
- services
- utils
- types
- templates
- webview
services:
location: src/services/
purpose: Business logic and data management
Expand Down Expand Up @@ -77,14 +77,17 @@ components:
depends_on:
- types
- utils
templates:
location: src/templates/
purpose: HTML template generation for webview UIs
webview:
location: src/webview/
purpose: Helpers and assets for the webview documents rendered by the providers
files:
detachedComponent.ts: Detached component view template
helpers/htmlBuilder.ts: HTML construction helper
helpers/styleBuilder.ts: CSS style helper
index.ts: Public exports
webviewHtml.ts: Nonce, Content-Security-Policy and asset-URI helpers for webview documents
inlineMarkdown.ts: HTML escaping and inline-Markdown rendering (vscode-free, unit-tested)
scriptData.ts: Safe JSON serialization for embedding data in a script block (vscode-free, unit-tested)
clientInlineMarkdown.ts: Source text for the browser-side twin of renderInlineMarkdown (vscode-free, unit-tested)
styles/: Stylesheets built to out/webview/styles/ and loaded via a CSP'd link
notes: Assets under styles/ (and client/ as scripts are extracted) are built by the webview esbuild
context and resolved at runtime through assetUri; they are not bundled into out/extension.js.
depends_on:
- types
constants:
Expand Down Expand Up @@ -213,8 +216,8 @@ data_flow:
component: componentService
action: Fetch component details (cache-first)
- step: 4
component: componentHtmlRenderer
action: Render documentation as HTML using templates/helpers
component: hoverContentBuilder
action: Build the hover markdown body (a MarkdownString, not HTML)
- step: 5
component: hoverProvider
action: Display hover card
Expand Down
36 changes: 36 additions & 0 deletions .ai/decisions.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -124,6 +124,42 @@ decisions:
- .release-it/vscode-version.js
- package.json (release:main, release:beta scripts)
title: Release It
DEPENDABOT_TARGETS_BETA:
date: '2026-09-14'
status: accepted
context: Dependabot defaulted to the repository default branch (main), which is the stable
release line. Bumps opened there duplicated what had already landed on beta, and a merge
to main auto-cuts a stable release.
decision: 'Set target-branch: "beta" on every ecosystem in .github/dependabot.yml (npm,
github-actions, pip)'
rationale:
- A push to main runs release-it with .release-it.json and cuts a stable GitHub release, so
a routine dependency bump merged there ships a release out of band
- main trails beta by everything not yet released, so bumps against main duplicate versions
beta already carries (e.g. #291/#292/#295 re-proposed bumps merged weeks earlier)
- Retargeting such a PR to beta conflicts on package-lock.json, since beta has moved
- Updates reach main the same way every other change does, through the beta -> main release PR
implementation:
config: '.github/dependabot.yml, target-branch: "beta" on each of the three package-ecosystem
entries'
flow: dependabot -> beta -> release PR -> main
alternatives_considered:
- name: leave_targeting_main
rejected_because: Ships stable releases from dependency bumps and produces duplicate PRs
- name: retarget_each_pr_by_hand
rejected_because: Lockfile conflicts on every npm PR; recurring manual work
consequences:
positive:
- Dependency updates follow the same path as feature work
- No stable release cut by a dependency bump
- No duplicate bumps against a stale branch
negative:
- A security fix reaches main only when the next release PR merges
references:
- .github/dependabot.yml
- .release-it.json
- .release-it.beta.json
title: Dependabot Targets Beta
MODULAR_SERVICE_SPLIT:
date: '2026'
status: accepted
Expand Down
3 changes: 2 additions & 1 deletion .ai/index.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,9 +25,9 @@ keys:
- providers
- scripts
- services
- templates
- types
- utils
- webview
workflows:
- add_configuration_option
- add_new_command
Expand All @@ -43,6 +43,7 @@ keys:
- BATCH_API_REQUESTS
- CACHE_COMPONENTS
- CENTRALIZED_ERROR_HANDLING
- DEPENDABOT_TARGETS_BETA
- EXTENSION_HOST_TEST_LAYER
- FILE_SIZE_POLICY
- MOCHA_OVER_JEST
Expand Down
1 change: 1 addition & 0 deletions .ai/workflows.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -145,6 +145,7 @@ common_commands:
debug: F5 (in VS Code)
package: npm run package
lint: npm run lint
lint_ci: npm run lint:ci (eslint + stylelint with GitHub annotation formatters; run by CI)
git_workflow:
branch_naming: feature/description or fix/description
commit_format: 'type(scope): description'
Expand Down
9 changes: 9 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,18 @@
# in osv-scanner.toml that the Argus scan honors. Do NOT add a dev-dep `ignore:` here to suppress
# those alerts -- `ignore:` also stops the version-update PRs below, which are how dev tools stay
# current and how a transitive fix (e.g. serialize-javascript >= 7.0.5) actually lands.
#
# Every ecosystem below sets `target-branch: "beta"`. Without it Dependabot opens against the default
# branch (`main`), which is the STABLE release line: a push there auto-cuts a stable GitHub release, so a
# routine dependency bump would ship one out of band. `main` also trails `beta` by whatever has not been
# released yet, so bumps opened against it duplicate what already landed on `beta` and conflict on the
# lockfile when retargeted. Everything reaches `main` through the beta -> main release PR instead.
version: 2
updates:
# Maintain npm dependencies
- package-ecosystem: "npm"
directory: "/"
target-branch: "beta"
schedule:
interval: "weekly"
day: "monday"
Expand Down Expand Up @@ -68,6 +75,7 @@ updates:
# Maintain GitHub Actions
- package-ecosystem: "github-actions"
directory: "/"
target-branch: "beta"
schedule:
interval: "weekly"
day: "monday"
Expand All @@ -85,6 +93,7 @@ updates:
# Maintain pre-commit hooks
- package-ecosystem: "pip"
directory: "/"
target-branch: "beta"
schedule:
interval: "weekly"
day: "monday"
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
run: npm ci

- name: Run lint
run: npm run lint
run: npm run lint:ci

- name: Run compile
run: node esbuild.js
Expand Down
6 changes: 4 additions & 2 deletions .github/workflows/security-hardening.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,10 @@ permissions:
jobs:
argus-hardening:
name: Argus Reusable Hardening
# Pinned to the commit for Argus v1.11.0 for supply-chain safety.
uses: huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml@9b444d8975f4a2253cc53e09a7c5837e5b509d24
# SHA-pinned rather than tag-pinned for supply-chain safety: a tag can be moved, a commit cannot.
# Dependabot bumps this SHA and names the tag it resolves to in the PR title, so read the version there
# rather than trusting a hand-written one here (this comment claimed v1.11.0 through three bumps past it).
uses: huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml@3fb133a5d03ec81a7a534cf451dd19991e04a975
with:
scanners: codeql,gitleaks,osv,dependency-review
enable_code_security: true
Expand Down
Loading