Skip to content

feat(changelog): publish curated product updates - #8787

Merged
waleedlatif1 merged 7 commits into
stagingfrom
codex/product-changelog
Oct 9, 2026
Merged

waleedlatif1 merged 7 commits into
stagingfrom
codex/product-changelog

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Replace raw release bullets with curated product updates. The index presents dates and linked titles in Sim’s shared landing typography, with up to 12 entries and a crawlable archive. Articles hold the useful detail and media, without personal bylines, repeated header summaries, card borders, or visible video descriptions.

  • Add deployment comparison, fork comparison, and Power BI updates using real product captures and contextual Sim integration/docs links. The two silent videos are edited walkthroughs from actual screenshots; the Power BI image demonstrates configuration without claiming an executed query.
  • Reuse the EMCN lightbox for screenshots and native controls for video. Keep responsive spacing, theme tokens, keyboard navigation, and accessible media labels.
  • Serve permanent article URLs, canonical metadata, structured data, sitemap entries, and stable RSS identities from one content registry. Development previews stay noindex and drafts stay off public routes and feeds. Validate media, publication dates, and integration/model/docs backlinks against the corresponding source catalogs.
  • Document story selection, real media production, editorial ownership, and maintenance. The Sim Internals workflow collects candidates, prepares and reviews drafts, verifies relevant links, preserves editorial edits, prepares actual recording assets, and monitors publication. Private exports and the operations runbook retain the live configuration; publication still requires feature-owner and editor review.
  • Use the existing trusted-PR checkout cache in the Helm job while preserving full history and the normal fork/push checkout path.

Validation

  • Browser QA: 320, 390, 768, 1024, and 1280px; light/dark themes; no horizontal overflow; shared lightbox zoom, Escape, and focus restoration; both videos play through and seek; no browser warnings or errors.
  • Real HTTP checks: canonical/schema consistency, crawlable list/archive links, draft exclusion, RSS identities, sitemap, live docs/integration destinations, and MP4 range responses. The 13-entry archive overflow scenario was also verified earlier in this PR.
  • Model-link regression cases were demonstrated failing before the fix and passing afterward. Local lint, type-check, all audits, docs manifest, block registry, and all 409 script tests pass. Nineteen workspace tasks passed locally; the duplicate full application run was stopped after more than 20 minutes without a final result. Its route-inventory timeout passed on isolated retry under the unchanged 60-second limit. The full CI test shards passed on this commit.
  • All 27 active CI checks passed at 038d86a1cb, including build, lint, both full test shards, database integration shards, CLI/SCIM E2E, desktop-live, and packaged Electron smoke. All review threads are resolved.
  • Live Sim verification: model-link preparation and editorial execution, deployed retry preserving the existing PR’s edited content, and healthy monitoring. Truncated model output fails closed. Captures and product availability remain a human editorial responsibility.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Relevant regression and end-to-end checks completed
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@waleedlatif1
waleedlatif1 requested a review from a team as a code owner October 8, 2026 06:15
@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 8, 2026 11:56pm UTC

Request Review

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 65 files

Confidence score: 4/5

  • apps/sim/lib/changelog/media.ts can let a padded src bypass the same-origin check and resolve to an external media URL. Reject tabs and newlines or normalize the value before checking its origin.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/lib/changelog/media.ts">

<violation number="1" location="apps/sim/lib/changelog/media.ts:7">
P3: The same-origin branch can be bypassed with ASCII tab/newline padding. The URL parser strips tab/newline before resolving, so `src` of `"/\n//evil.com/x.mp4"` passes the guard (starts with `/`, second char is `\n` not `/`) but resolves to `https://evil.com/x.mp4`, defeating the media-origin allowlist and the CSP `media-src` restriction. Strip ASCII tabs/newlines from the string before the prefix check.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/app/changelog.xml/route.ts Outdated
Comment thread apps/sim/lib/changelog/media.ts
@greptile-apps

greptile-apps Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium impact] The PR appears safe to merge; the revised guide preserves saved editor decisions.

Summary

Replaces GitHub release bullets with curated product updates, permanent article pages, an archive, and shared RSS and sitemap content.

  • Adds reviewed product media, local draft previews, content checks, and publishing guidance.
  • Proposes a weekly editorial workflow without activating it.
  • The latest change fixes the earlier saved-decisions concern: the guide now uses inserts for new records and partial updates for existing records.
  • No new actionable issues were found.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Reviewed MDX and media] --> B[Published content registry]
  B --> C[Latest updates and archive]
  B --> D[Permanent article pages]
  B --> E[RSS and sitemap]
  F[Draft content] --> G[Development-only previews]
Loading

Reviews (5) · Last reviewed commit: "fix(changelog): preserve editorial decis..." · Reviewed by Greptile

@waleedlatif1
waleedlatif1 force-pushed the codex/product-changelog branch from eae55a5 to 4472afc Compare October 8, 2026 06:54
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 66 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the codex/product-changelog branch from 4472afc to 2bd4360 Compare October 8, 2026 16:24
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 66 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

Document scheduled discovery, durable candidate state, draft PR preparation, real-media review, and operational checks. Reuse the existing cached checkout for trusted Helm PR checks while preserving full history.
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 68 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/content/changelog/maintenance-workflow.md Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 68 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit d0d00b1 into staging Oct 9, 2026
54 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/product-changelog branch October 9, 2026 00:54

This branch was successfully deployed

1 active deployment
Preview — 038d86a1 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant