Skip to content

add project dependency packaging - #19530

Open
andz-bb wants to merge 31 commits into
masterfrom
codex/project-dependencies-packaging
Open

andz-bb wants to merge 31 commits into
masterfrom
codex/project-dependencies-packaging

Conversation

@andz-bb

@andz-bb andz-bb commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Description

adds the dependency and package foundation for projects.

  • discovers dependencies from structured references without treating ordinary text as a dependency
  • packages assigned resources with their owned content, preserving deliberate exclusions
  • validates packages and remaps resource, view and row-action references into the destination workspace
  • removes credentials and records setup requirements for imported resources
  • bounds archive extraction and encrypted expansion, locks package operations and rolls back incomplete imports

covers owner exclusions, malformed packages, credential removal, remapping and import cleanup with API tests.

part 1 of the six-part projects stack. review against master. next: #19245.

Addresses

App Export

  • n/a

Screenshots

  • n/a

Launchcontrol

improves project export and import reliability, including portable views and credential removal

@andz-bb andz-bb changed the title Harden Project dependency graph and packages add project dependency packaging Aug 24, 2026
@andz-bb
andz-bb force-pushed the codex/project-dependencies-packaging branch from 185545c to 84d2d6b Compare August 25, 2026 13:32

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 18 files

Tip: instead of fixing issues one by one fix them all with cubic

Re-trigger cubic

Comment thread packages/server/src/sdk/workspace/resources/references.ts Outdated
Comment thread packages/server/src/sdk/workspace/resources/references.ts Outdated
Comment thread packages/server/src/sdk/workspace/datasources/datasources.ts Outdated
Comment thread packages/server/src/sdk/workspace/resources/index.ts Outdated
Comment thread packages/server/src/sdk/workspace/projects/backups/imports.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 19 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread packages/server/src/sdk/workspace/resources/references.ts Outdated
Comment thread packages/server/src/sdk/workspace/projects/backups/exports.ts Outdated
Comment thread packages/server/src/sdk/workspace/resources/references.ts Outdated
Comment thread packages/server/src/sdk/workspace/projects/lock.ts
@andz-bb andz-bb linked an issue Aug 25, 2026 that may be closed by this pull request
@andz-bb
andz-bb force-pushed the codex/project-dependencies-packaging branch from ea29f10 to 514d238 Compare August 27, 2026 10:39

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 25 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread packages/server/src/sdk/workspace/resources/references.ts
Comment thread packages/server/src/sdk/workspace/datasources/datasources.ts
Comment thread packages/server/src/sdk/workspace/projects/crud.ts
@andz-bb

andz-bb commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai rerun

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai rerun

@andz-bb I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 25 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 25 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@andz-bb
andz-bb force-pushed the codex/project-dependencies-packaging branch from 822d645 to 8b5b8bf Compare September 2, 2026 08:59
@andz-bb

andz-bb commented Sep 5, 2026

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai rerun

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai rerun

@andz-bb I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 27 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread packages/server/src/sdk/workspace/automations/utils.ts
@andz-bb

andz-bb commented Sep 5, 2026

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai rerun

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai rerun

@andz-bb I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 27 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread packages/server/src/sdk/workspace/projects/backups/imports.ts
Comment thread packages/server/src/api/routes/tests/project.spec.ts
@andz-bb

andz-bb commented Sep 5, 2026

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai rerun

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai rerun

@andz-bb I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 28 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Re-trigger cubic

@andz-bb

andz-bb commented Sep 5, 2026

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai rerun

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai rerun

@andz-bb I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 issues found across 28 files

Confidence score: 3/5

  • In packages/server/src/sdk/workspace/projects/backups/exports.ts, legacy datasources assigned only via an external table’s projectIds may be omitted from exports and their dependencies, causing incomplete packages; preserve coverage for this assignment path and verify the export includes the datasource content and dependencies.
  • In packages/server/src/api/routes/tests/resource.spec.ts, replacing the duplication test removes coverage for datasource duplication without its project, which could allow external-table project assignments to regress unnoticed; retain a case covering duplication without the project.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="packages/server/src/sdk/workspace/projects/backups/exports.ts">

<violation number="1" location="packages/server/src/sdk/workspace/projects/backups/exports.ts:96">
P2: For legacy datasources assigned only through an external-table entity's `projectIds`, this export no longer treats the datasource as a direct member, so its content is silently omitted from the package and dependency index. The removed `getProjectAssignedEntities` path previously kept them. Confirm whether pre-migration entity-only assignments are still expected to export, and preserve their inclusion.</violation>
</file>

<file name="packages/server/src/api/routes/tests/resource.spec.ts">

<violation number="1" location="packages/server/src/api/routes/tests/resource.spec.ts:1124">
P2: This change removes the test "removes external table project assignments when duplicating a datasource without its project" and replaces it with a version that duplicates the datasource together with its project. As a result, the entity-level stripping path (external table `entities[*].projectIds` removed when a project-member datasource is duplicated on its own, without the project) is no longer covered. Only the with-project case is now pinned; datasource-level stripping without the project is covered by a different test but it has no external-table entities. Keep a separate case that duplicates the datasource without the project and asserts the external-table `projectIds` are stripped.</violation>
</file>

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Fix all with cubic | Re-trigger cubic

Comment thread packages/server/src/sdk/workspace/projects/backups/exports.ts
Comment thread packages/server/src/api/routes/tests/resource.spec.ts Outdated
@github-actions github-actions Bot added the stale label Sep 12, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 35 files

Tip: instead of fixing issues one by one fix them all with cubic

Re-trigger cubic

Comment thread packages/server/src/sdk/workspace/resources/index.ts Outdated
Comment thread packages/server/src/api/controllers/project.ts Outdated
Comment thread packages/server/src/sdk/workspace/resources/references.ts Outdated
Comment thread packages/server/src/sdk/workspace/resources/references.ts Outdated
Comment thread packages/server/src/sdk/workspace/backups/imports.ts
Comment thread packages/server/src/sdk/workspace/projects/backups/imports.ts
Comment thread packages/server/src/sdk/workspace/projects/backups/exports.ts
Comment thread packages/server/src/sdk/workspace/projects/tests/lock.spec.ts
Comment thread packages/backend-core/src/security/tests/encryption.spec.ts Outdated
@andz-bb
andz-bb force-pushed the codex/project-dependencies-packaging branch from 86195ef to 7ea754f Compare September 23, 2026 12:19
@github-actions github-actions Bot removed the stale label Sep 23, 2026
andz-bb added 28 commits October 1, 2026 11:18
@andz-bb
andz-bb force-pushed the codex/project-dependencies-packaging branch from b159e03 to a187ec1 Compare October 1, 2026 10:26

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Projects

2 participants