Skip to content

Update dependency @tailor-platform/sdk to v2.26.0 - #128

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/tailor-platform-sdk-2.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/tailor-platform-sdk-2.x

Conversation

@renovate

@renovate renovate Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@tailor-platform/sdk (source) 2.22.0 → 2.26.0 age confidence

Release Notes

tailor-platform/sdk (@​tailor-platform/sdk)

v2.26.0

Compare Source

Minor Changes
  • #​2525 d21806e Thanks @​dqn! - These state-changing commands now print a JSON result on stdout under --json instead of leaving it empty: authconnection delete, authconnection revoke, organization folder delete, secret create, secret update, secret delete, secret vault delete, workspace delete, workspace restore, workspace user remove, tailordb truncate, tailordb migration set, tailordb migration rebaseline, tailordb migration sync, and tailordb migration generate. Each result carries the same changed boolean as the other commands: for example, tailordb migration set to the checkpoint and migration history ID already in place, and tailordb migration generate with no migration to write, report false. Under --json, tailordb migration generate and tailordb migration script no longer open the file they create in the editor set by VISUAL or EDITOR, which would otherwise write to the same stdout. Output without --json is unchanged.

  • #​2470 090297d Thanks @​toiroakr! - Add a temporal option to kyselyTypePlugin. When enabled, date/datetime fields and top-level time fields resolve to Temporal.PlainDate/Temporal.Instant/Temporal.PlainTime (instead of Date/string) in generated Kysely types, migration db.ts files, and tailor function script types, and the generated getDB() reads them back as those values. Nested time fields remain strings. The mode is fixed by the plugin setting; getDB() takes no temporal option.

    Each migration records whether its db.ts was generated with Temporal types, and deploy runs that migration's script in the same mode, so migrations generated before temporal was enabled keep receiving Date values. Migration files are now written as format version 7, which older SDK versions refuse to read. mockTailordbWithPGlite and createKyselyPGlite (with { temporal: true }) return Temporal values from PGlite to match, and accept Temporal values as query parameters.

v2.25.0

Compare Source

Minor Changes
  • #​2449 e4a0301 Thanks @​toiroakr! - tailor open and tailor auth-connection open now always open the new Tailor Platform Console UI, which has replaced the previous UI at console.tailor.tech. tailor open opens /workspaces/{workspaceId}/services/applications/{applicationName} (previously /workspaces/{workspaceId}/applications/{applicationName}/overview), and tailor auth-connection open opens /workspaces/{workspaceId}/services/auth-connections (previously /workspaces/{workspaceId}/settings/connections). The TAILOR_CONSOLE_NEXT environment variable is no longer read: a leftover TAILOR_CONSOLE_NEXT=1 no longer redirects the console host to console-next., so it can be removed.

  • #​2468 3c87be0 Thanks @​toiroakr! - Add an onDeployed plugin hook with deployed application IDs and URLs, public OAuth client IDs, and publishing to static websites. Hooks run after successful deploys, including deploys without resource changes, and can return structured JSON outputs.

  • #​2468 7451944 Thanks @​toiroakr! - Add frontendPlugin from @tailor-platform/sdk-plugin-frontend to build and upload frontend assets during tailor deploy. Frontend builds can use deployed URLs and public OAuth client IDs as environment variables, and deployment results include uploaded frontend details in outputs.frontends.

    Add deployment hooks and shared context types to @tailor-platform/sdk. Successful tailor deploy --json results now include workspaceId and applications with deployed application, Static Website, and AI Gateway URLs, plus public OAuth client IDs, even when no deploy plugins are configured.

  • #​2505 3296f08 Thanks @​dqn! - More state-changing commands now print a JSON result on stdout under --json, so scripts can confirm what changed without parsing stderr: login, logout, remove, profile delete, user switch, user pat delete, secret vault create, authconnection authorize, workspace user invite, workspace user update, workspace ttl set, workspace ttl clear, crashreport send, and tailordb migration script. Each result carries a changed boolean: true when the command did work, false when it did nothing, such as logout when nobody is logged in, user switch to the current user, or workspace ttl clear on a workspace with no TTL. Output without --json is unchanged.

  • #​2497 efcca78 Thanks @​tailor-bobbin! - Include the machine user id in tailor machineuser list output so machine users can be matched against the invoker id available in resolvers and executors.

  • #​2486 caa34b4 Thanks @​dqn! - tailor secret create and tailor secret update now read the secret value from standard input when --value is omitted, keeping it out of shell history and process listings: printf '%s' "$VALUE" | tailor secret create --vault-name <vault> --name <name>. The piped value can be up to 128 KiB, and one trailing newline is removed from it. Without --value, a terminal or empty standard input fails with SECRET_VALUE_REQUIRED.

  • #​2485 d06f314 Thanks @​dqn! - tailor show (and the programmatic show()) now also lists each deployed static website defined in staticWebsites with its URL and description, and each deployed OAuth2 client defined in auth's oauth2Clients with its client ID, so a CI step can read both from one tailor show --json call right after tailor deploy. Client secrets are never included. Credentials that cannot list OAuth2 clients, such as the workspace viewer role, get a warning and oauth2Clients: null, which sets that case apart from an application with no deployed OAuth2 clients.

Patch Changes
  • #​2487 d160c86 Thanks @​dqn! - Declining a confirmation prompt now makes the command exit non-zero with a *_CANCELLED error code, as tailor deploy and tailor remove already did, instead of exiting 0 as if the operation had succeeded. This covers workspace delete / restore / prune, workspace user remove, organization folder delete, secret create / update / delete, secret vault delete, authconnection delete / revoke, tailordb truncate, and tailordb migration generate / set / sync / rebaseline. For example, tailor workspace delete reports WORKSPACE_DELETION_CANCELLED when the entered name does not match, and tailor tailordb migration generate still generates the other namespaces before reporting MIGRATION_GENERATE_CANCELLED for the ones whose breaking changes were declined. Confirmation prompts appear only in an interactive terminal, so runs with --yes, in CI, or with --json are unaffected. migrateGenerate() now rejects with MIGRATION_GENERATE_CANCELLED when its prompt is declined, instead of resolving or exiting the process.

  • #​2484 7454455 Thanks @​dqn! - tailor init now exits non-zero when project scaffolding fails, instead of exiting 0. It reports INIT_FAILED when create @tailor-platform/sdk exits with a non-zero code or is terminated by a signal, and INIT_SPAWN_FAILED when the package manager cannot be started.

  • #​2488 608b7eb Thanks @​dqn! - Argument errors now follow --json and TAILOR_JSON_OUTPUT. An unknown option or subcommand, or an option value that fails validation, was printed as plain text even when JSON output was requested, because it happened before the flag took effect. It is now reported as the usual JSON error envelope on stderr with the code INVALID_ARGUMENTS, for example {"error":{"code":"INVALID_ARGUMENTS","message":"Unknown flags: bogus"}}. --verbose now also applies to these errors, adding the stack trace to the envelope or to the plain-text output, as it does for other failures. Otherwise, output without JSON mode is unchanged.

  • #​2506 69b3234 Thanks @​dqn! - List commands now say when --limit cut their output short. When more items exist than --limit allows, the list is followed by More results exist beyond --limit N. Raise --limit to see more. on stderr, so a caller can tell a complete list from a partial one; stdout, including --json output, is unchanged. This matters most for executor jobs, function logs, and workflow executions, which list 50 items unless --limit says otherwise.

  • #​2492 46590a4 Thanks @​renovate! - fix(deps): update oxc

  • #​2515 ef00996 Thanks @​renovate! - chore(deps): lock file maintenance

  • #​2517 3220bc9 Thanks @​renovate! - fix(deps): update dependency rolldown to v1.2.12

  • #​2483 ae6451e Thanks @​toiroakr! - tailor setup ci branch, tailor setup ci tag, and tailor setup ci preview accept --dir more than once. The generated workflow deploys every app to the same workspace in one multi-config run from the repository root, runs the generate check for each app directory (plus seed validation and the migration drift check on branch and tag workflows), and runs its jobs on changes under any of them. --name is required when --dir is repeated, and the root package.json must declare @tailor-platform/sdk. With --erd-preview, each TailorDB namespace is previewed from the app that owns it.

    tailor setup ci branch and tailor setup ci preview also accept --paths (repeatable) to run the generated jobs on changes outside the app directories, such as a frontend or shared packages. A pattern supports *, **, and a leading ! to exclude paths; other glob characters are rejected.

    Branch and preview workflows with an app directory other than the repository root no longer filter their on: triggers by paths. Branch workflows start on every pull request and push, preview workflows on every pull request, and a new tailor-changes job skips the plan, deploy, and preview jobs when nothing under the app directories (or --paths) changed. Skipped jobs report success, so these checks can be required in branch protection. If the tailor-changes job itself fails, those jobs fail instead of being skipped, so a required check cannot pass without them. setup remains a beta command, so this ships as an immediate change rather than going through a deprecation cycle.

    Branch workflows generated with --erd-preview now install the project dependencies before building the ERD preview, which the setup step does not do.

    The workflow template version is bumped, so tailor setup check reports every generated target as outdated; run tailor setup update to regenerate them. Branch and preview workflows whose --dir is not the repository root switch to the tailor-changes job described above, and branch workflows generated with --erd-preview get the new ERD matrix and install step. Other workflows regenerate identically. tailor setup update keeps every app directory and --paths pattern of a multi-directory target.

  • #​2489 16175f6 Thanks @​toiroakr! - You can add environment: to a managed job that tailor setup ci generates without one (tailor-tag-guard, and the tailor-erd-preview* jobs from --erd-preview), so a step you added there can read that GitHub Environment's secrets, such as a token for installing dependencies from a private registry. tailor setup check no longer reports it as a hand edit, and re-running tailor setup ci keeps it. The environment: of tailor-plan, tailor-deploy, and the preview jobs still comes from --environment.

v2.24.0

Compare Source

Minor Changes
  • #​2459 72e295b Thanks @​toiroakr! - When a resolver, executor, or workflow job fails to build with FORBIDDEN_RUNTIME_GLOBAL because it references a Node-only global such as process or Buffer, the error now names where the reference is: the file in your own code, or the installed package (code under node_modules). A reference from an installed package can be allowed with the new buildOptions.allowedRuntimeGlobals option of defineConfig(), keyed by package name, with the globals to allow or true for all of them — for example buildOptions: { allowedRuntimeGlobals: { "@ai-sdk/gateway": ["Buffer"] } } — once you have confirmed that the package's code referencing it never runs for your use. The error's suggestion shows the entry to add. buildOptions.allowedRuntimeGlobals has no effect on your own code.

  • #​2463 f708521 Thanks @​toiroakr! - defineConfig() accepts buildOptions, which groups the settings that control how resolvers, executors, workflow jobs, and other functions are bundled: inlineSourcemap, logLevel, and allowedRuntimeGlobals. The top-level inlineSourcemap and logLevel still work but are deprecated and will be removed in v3; tailor upgrade moves them into buildOptions with the v3/define-config-build-options codemod. Setting the same option both at the top level and in buildOptions fails config validation instead of silently using one of them.

    export default defineConfig({
      name: "my-app",
      buildOptions: {
        inlineSourcemap: false,
        logLevel: "WARN",
      },
    });
Patch Changes
  • #​2475 10ab737 Thanks @​toiroakr! - Generated deploy jobs now expose the deployed workspace as job outputs, so a job of your own can use needs: to run tests or deploy extra assets against it:

    • tailor setup ci preview: the tailor-preview-deploy job exposes workspace-id, workspace-name, and app-url of the per-PR workspace.
    • tailor setup ci branch and tailor setup ci tag: the tailor-deploy job exposes workspace-id and app-url.

    tailor setup check reports the template as outdated; run tailor setup update to regenerate every target.

  • #​2464 978c332 Thanks @​renovate! - fix(deps): update secretlint monorepo to v13.0.6

  • #​2465 d8222e4 Thanks @​renovate! - chore(deps): update dependency @​​types/node to v24.19.0

  • #​2458 e982853 Thanks @​toiroakr! - Deploying a resolver, executor, or workflow no longer fails with FORBIDDEN_RUNTIME_GLOBAL for a Node-only global such as process that is only used after checking that it exists — for example if (typeof process !== "undefined") { ... process.env.FOO ... }, an early exit such as if (typeof process === "undefined") return; followed by process.env.FOO, or typeof process < "u" && process.emitWarning(message). A global used without such a check is still reported — for example the Buffer.from(...) inside @ai-sdk/gateway, which the Vercel AI SDK (ai) depends on.

  • #​2457 be6ffb2 Thanks @​toiroakr! - Fix workflow.start() and job .start() calls that built and deployed but threw "workflow.start() is rewritten at build time and unavailable in the bundle" at runtime. These calls are now rewritten when:

    • the workflow file is imported through a tsconfig.json compilerOptions.paths alias (e.g. import workflow from "@/workflow/syncGLBalances")
    • the workflow is default-exported as the result of a helper function that calls createWorkflow() (e.g. export default module.workflows.syncGLBalances.create(mainJob)); wrapping the helper result in another createWorkflow({ ...helperResult, name: "..." }) call is no longer needed
    • the workflow file is imported as a namespace (import * as wf from "./workflows/sync"; wf.default.start(...))

    A .start() call on an import from a workflow file that still cannot be rewritten — such as a helper-created workflow exported under a named export — now fails the build instead of deploying code that throws at runtime. The runtime error for an unrewritten workflow.start() also names the workflow.

v2.23.0

Compare Source

Minor Changes
  • #​2440 e2df6cf Thanks @​dqn! - tailor deploy now marks updates that show no configuration difference and are applied again only because the application's resources were last deployed with a different SDK version. The plan lists them with [forced by SDK version] and the summary counts them (12 to update (11 forced by SDK version)), so after an SDK upgrade you can tell them apart from real configuration changes. With --json, such changes carry forcedBySdkVersion: true and summary.forcedBySdkVersion counts them.
Patch Changes
  • #​2442 4a974b1 Thanks @​dqn! - Fix the tailor deploy plan leaving out workflow execution policies: their changes are now listed in the Workflow section, and unmanaged or conflicting execution policies and applications now appear in the plan's warnings and owner conflicts, including --json output.

  • #​2462 551179a Thanks @​k1LoW! - Function execution logs are now read from the platform's structured log entries instead of the deprecated flat logs field. The logs string that function run, function logs --json, workflow executions --logs, executor jobs --logs, TailorDB migrations, and executeScript() return joins the messages of those entries with newlines, and function logs no longer falls back to the flat string when an execution has no structured entries.

  • #​2448 317ba1e Thanks @​renovate! - fix(deps): update dependency rolldown to v1.2.11

  • #​2438 feb8b23 Thanks @​dqn! - On Windows, a suggested follow-up command whose arguments cmd.exe and PowerShell read differently (for example a profile named dev$1, a config path containing %, or the webhook trigger's JSON body) is now shown as one command to copy into PowerShell and one to copy into cmd.exe, instead of an argv [...] array or a double-quoted line that PowerShell misreads. The tailor profile update suggestions shown for a read-only profile or a denied machine-user override now quote the profile name instead of pasting it into the command unquoted. On every platform, these suggested follow-up commands are now set off in backticks.

  • #​2462 0dcbed6 Thanks @​k1LoW! - Workflow commands now recognize canceled workflow executions. workflow start --wait, workflow wait, workflow executions <id> --wait, and executor jobs --wait over a workflow stop at a canceled execution and fail with WORKFLOW_EXECUTION_CANCELED instead of polling until they time out, a TailorDB migration whose workflow is canceled fails instead of waiting indefinitely, the status is shown as CANCELED rather than UNSPECIFIED, and workflow executions --status CANCELED is accepted.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 29, 2026 16:08
@renovate renovate Bot changed the title Update dependency @tailor-platform/sdk to v2.23.0 Update dependency @tailor-platform/sdk to v2.24.0 Oct 2, 2026
@renovate
renovate Bot force-pushed the renovate/tailor-platform-sdk-2.x branch 2 times, most recently from 6c16898 to c0b7482 Compare October 5, 2026 05:57
@renovate renovate Bot changed the title Update dependency @tailor-platform/sdk to v2.24.0 Update dependency @tailor-platform/sdk to v2.25.0 Oct 5, 2026
@renovate
renovate Bot force-pushed the renovate/tailor-platform-sdk-2.x branch from c0b7482 to f146730 Compare October 6, 2026 10:10
@renovate renovate Bot changed the title Update dependency @tailor-platform/sdk to v2.25.0 Update dependency @tailor-platform/sdk to v2.26.0 Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants