Skip to content

CLI: Update SDK to 2f367635f58ffca59a764f8a8280784fb0f9f7e7 and add new commands/flags - #278

Open
kernel-internal[bot] wants to merge 11 commits into
mainfrom
cli-coverage-update
Open

kernel-internal[bot] wants to merge 11 commits into
mainfrom
cli-coverage-update

Conversation

@kernel-internal

@kernel-internal kernel-internal Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR updates the Go SDK to 2f367635f58ffca59a764f8a8280784fb0f9f7e7 and adds CLI commands/flags for new SDK methods.

SDK Update

  • Updated kernel-go-sdk to 2f367635f58ffca59a764f8a8280784fb0f9f7e7 (v0.119.0)
  • The latest SDK change (73817c0 → 2f36763) is the v0.119.0 release and changes only release metadata: version, changelog, and README. api.md and the Go sources are unchanged, so this change adds no new methods or params.
  • The previous SDK change (681b969 → 73817c0) adds the managed_auth credential vault item provider (ManagedAuthCredentialVaultItemSpecInputParam, ManagedAuthCredentialVaultItemSpec, ManagedAuthCredentialVaultItemState). It adds no new methods.

Coverage Analysis

This PR was generated by performing a full enumeration of SDK methods and CLI commands. All 172 SDK methods in api.md have CLI coverage, except the ConfigRegistry endpoints, which are marked x-cli-skip. kernel search (get/providers/contents) and kernel browsers curl cover the Search and Curl methods through raw requests.

New Commands

  • None (no new SDK methods)

New Flags / Spec Options

  • kernel vaults credentials create --spec-file now accepts {"provider":"managed_auth","connection_id":"...","description":"..."} for CredentialVaultItemSpecInputUnionParam.OfManagedAuth (ManagedAuthCredentialVaultItemSpecInputParam.ConnectionID, .Description). A missing connection_id is rejected before the request is sent.
  • Display-safe vault JSON output keeps spec.connection_id and state.fields[*].type, and no longer rewrites managed_auth state fields with has_value. Table output shows the managed auth connection and a fill hint. The help text and README document the flow.

These came from earlier commits on this branch (SDK a1378239c479):

  • --provider kernel on kernel vaults wallets create for WalletVaultItemSpecUnionParam.OfKernel (KernelWalletVaultItemSpecParam): Kernel-managed agentic network token wallet with hosted card enrollment. Provider config and --tokens-file are rejected for this provider.
  • --provider kernel on kernel vaults cards create for CardVaultItemSpecUnionParam.OfKernel (KernelCardVaultItemSpecParam: wallet, amount, currency, merchant_name, merchant_url). cards update rejects Kernel cards because the API doesn't support updating them.
  • --query on kernel vaults list for VaultListParams.Query.
  • Spec help now documents KernelWalletSpec and KernelCardSpec.
  • Item output shows the merchant URL, card last4, and network token last4 (masks.token_last4); filtered JSON output keeps token_last4.

Testing

  • SDK bump to 2f36763: go build ./..., go vet ./... and go test ./... pass. This change adds no new commands or flags, so there was nothing new to smoke test.
  • vaults credentials create with a managed_auth spec, run against the live API using an existing connection with a saved credential: the item was created ready with the fill operation advertised. items get (table and JSON) showed connection_id and the field binding types (email, password, sms_code), and items list showed provider managed_auth.
  • Error paths: a missing connection_id is rejected client-side, and an unknown connection returns 404.
  • Cleanup: deleted the item and the temporary vault, and confirmed the connection and its credential were unchanged.
  • Unit tests added (cmd/vaults_managed_auth_test.go); go test ./... and go vet ./... pass.
  • Earlier commits: vaults wallets create --provider kernel sent its request, but the staging API answered provider configuration is unavailable. vaults cards create --provider kernel reached the API, which validated the kernel card spec.

Triggered by: kernel/kernel-go-sdk@2f36763
Reviewer: @bmsaadat

🤖 Generated with Claude Code


Note

High Risk
Adds managed-auth credential binding, Kernel card/wallet flows, and webmcp_invoke with vaulted secrets and possible page side effects—all security- and payment-sensitive paths.

Overview
Bumps kernel-go-sdk to v0.119.0 and expands vault/credential CLI support for new API providers and operations.

Vault credentials can be created with managed_auth (connection_id + optional description): no stored values; fill reads the linked auth connection’s saved credential at runtime. Parsing, help, table/JSON output, and tests cover the new provider.

Vault items gain webmcp_invoke (--params / --spec-file): bind vaulted fields into a WebMCP tool call on a vault-bound browser session, with validation, no retries on uncertain outcomes, and status-based exit codes. Docs and README list it alongside fill / collect.

Kernel payment provider is wired for vaults wallets create and vaults cards create (--provider kernel); Kernel wallets reject provider config/tokens; cards update is blocked for Kernel items. Output/docs add merchant URL and card/network token last4 fields.

kernel vaults list adds --query (name substring / exact ID), preserved in pagination hints. kernel credentials table output shows TOTP algorithm/digits/period when configured. kernel logs only sends --since when the flag was explicitly set.

Unit tests cover WebMCP invoke, managed auth, Kernel wallet validation, vault list query, and TOTP algorithm normalization.

Reviewed by Cursor Bugbot for commit 21ce1a2. Bugbot is set up for automated code reviews on this repo. Configure here.

SDK version bump only. A full enumeration of SDK methods vs CLI commands
found no coverage gaps (config-registry endpoints are x-cli-skip).

Tested: go build ./... (no new commands/flags to smoke test)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@socket-security

socket-security Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang/​github.com/​kernel/​kernel-go-sdk@​v0.116.0 ⏵ v0.119.073 +1100100100100

View full report

- Bump github.com/kernel/kernel-go-sdk to 10c4031082d73b41180adeb54a722f89341907ff
- Add --totp-algorithm, --totp-digits, --totp-period to `kernel credentials create`
  and `kernel credentials update` (CreateCredentialRequestParam /
  UpdateCredentialRequestParam TotpAlgorithm, TotpDigits, TotpPeriod)
- Show TOTP algorithm/digits/period in credentials get/create output

Tested: credentials create --totp-secret --totp-algorithm sha256 --totp-digits 8
--totp-period 60 (8-digit code returned, metadata shown in get), credentials
totp-code, credentials update --totp-secret --totp-algorithm SHA512 --totp-digits 7
(verified in get -o json), invalid --totp-algorithm rejected, otpauth:// URI
params take precedence over explicit flags, credentials delete cleanup.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update Go SDK to 820e4fed1c2963e3dea2b6159640c4d855f82cde CLI: Update SDK to 10c4031082d73b41180adeb54a722f89341907ff and add new commands/flags Oct 1, 2026
Bumps kernel-go-sdk to v0.116.0 (c026e806a1bd). The SDK changes since
10c4031082d7 are release metadata only. A full enumeration of SDK
methods against CLI commands found no coverage gaps. Config-registry
endpoints are x-cli-skip.

Tested: go build ./..., go test ./... (SDK version bump only, no new commands/flags)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to 10c4031082d73b41180adeb54a722f89341907ff and add new commands/flags CLI: Update SDK to c026e806a1bdffd330b0f533d5f132d7d9b0e5aa and add new commands/flags Oct 1, 2026
kernel-internal Bot and others added 2 commits October 2, 2026 13:25
- Bump github.com/kernel/kernel-go-sdk to 615cfaf0c5a80549cba3cd643c00b58c517f5475
- Add `webmcp_invoke` to `kernel vaults items invoke` (--params/--spec-file
  with browser_id, tool_ref, page_url, input, bindings, timeout_sec) for
  WebmcpInvokeVaultItemOperationRequestParam / VaultWebmcpBindingParam

Tested: created vault + credential (populated via hosted collect form),
vault-bound browser with a custom WebMCP tool on example.com;
`vaults items invoke <vault> login webmcp_invoke --params ...` (table) and
`--spec-file - -o json` both returned completed with vaulted values
substituted; mismatched page_url returned HTTP 400 with guidance. Resources
cleaned up.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to c026e806a1bdffd330b0f533d5f132d7d9b0e5aa and add new commands/flags CLI: Update SDK to 615cfaf0c5a80549cba3cd643c00b58c517f5475 and add new commands/flags Oct 2, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dced2d6. Configure here.

Comment thread cmd/credentials.go
Comment thread cmd/credentials.go
Comment thread cmd/credentials.go
SDK bump only (v0.117.0 release; no API changes). Full enumeration of
SDK methods vs CLI commands found no coverage gaps.

Tested: go build, go test ./cmd/..., kernel browsers list

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to 615cfaf0c5a80549cba3cd643c00b58c517f5475 and add new commands/flags CLI: Update SDK to a6798c8e6ccf5e701517face8497e522c6bba83e and add new commands/flags Oct 2, 2026
- Bump kernel-go-sdk to 0aa2b3c772eb7eff991947d84a8f0bbb3a879abe
- Add --query to `kernel vaults list` (VaultListParams.Query); preserved in Next: hint
- Forward explicit --since to InvocationFollowParams.Since in `kernel logs --invocation`

Tested: vaults create/list --query (substring match, no match, -o json)/delete;
logs <app> --invocation <id> [--since 1h]; go test ./...

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to a6798c8e6ccf5e701517face8497e522c6bba83e and add new commands/flags CLI: Update SDK to 0aa2b3c772eb7eff991947d84a8f0bbb3a879abe and add new commands/flags Oct 2, 2026
Update kernel-go-sdk to a1378239c479aeeb6d360e0719426ff0c9821da6.

- vaults wallets create / cards create: accept --provider kernel
  (KernelWalletVaultItemSpecParam, KernelCardVaultItemSpecParam)
- Reject provider config/tokens-file for Kernel wallets and updates for
  Kernel cards (unsupported per API)
- Document KernelWalletSpec and KernelCardSpec in spec help
- Show merchant URL, card last4, and network token last4 (masks.token_last4)
  in item output; keep token_last4 in filtered JSON

Tested: vaults wallets create --provider kernel (request forwarded; staging
API returned "provider configuration is unavailable"), vaults cards create
--provider kernel (API validated kernel spec), client-side rejection of
cards update/provider-config for kernel, items get output, vault cleanup.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to 0aa2b3c772eb7eff991947d84a8f0bbb3a879abe and add new commands/flags CLI: Update SDK to a1378239c479aeeb6d360e0719426ff0c9821da6 and add new commands/flags Oct 2, 2026
Bump kernel-go-sdk to v0.118.0 (681b969). The SDK change is a release
only (no API surface changes); full enumeration found no coverage gaps.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to a1378239c479aeeb6d360e0719426ff0c9821da6 and add new commands/flags CLI: Update SDK to 681b969b9d242674ecd59d40f488c9e7c50b607f and add new commands/flags Oct 2, 2026
Bump kernel-go-sdk to 73817c0b9c4e93502daf9ecaa0bcf27e11e827bb, which adds
the managed_auth credential vault item spec (ManagedAuthCredentialVaultItemSpecInputParam).

- vaults credentials create accepts spec provider "managed_auth" with
  connection_id and optional description
- Display-safe vault output keeps spec.connection_id and state.fields[*].type,
  and no longer rewrites managed_auth state fields with has_value
- Table output shows the managed auth connection; help/README document the flow

Tested: vaults credentials create --spec-file (provider managed_auth) against
the live API, then vaults items get (table + json), vaults items list, missing
connection_id validation, unknown connection (404), cleanup via items delete and
vaults delete. go test ./... passes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to 681b969b9d242674ecd59d40f488c9e7c50b607f and add new commands/flags CLI: Update SDK to 73817c0b9c4e93502daf9ecaa0bcf27e11e827bb and add new commands/flags Oct 2, 2026
…9.0)

Full enumeration of SDK methods vs CLI commands found no coverage gaps;
the SDK change contains only release metadata (version/changelog).

Tested: go build ./..., go vet ./..., go test ./...

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to 73817c0b9c4e93502daf9ecaa0bcf27e11e827bb and add new commands/flags CLI: Update SDK to 2f367635f58ffca59a764f8a8280784fb0f9f7e7 and add new commands/flags Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants