Repository navigation
Bump stevecastaneda/history to 0.4.3 - #294
Conversation
There was a problem hiding this comment.
History 0.4.3 needs one interface screenshot before publication, @stevecastaneda. Your bundled dependency fixes the earlier packaging blocker, and your overview is suitable. I added your existing icon to the listing.
Reply here with a public HTTPS PNG/JPG/WebP/GIF URL showing the History window, and I’ll add it to listing.media in plugins/stevecastaneda/history.json. An icon alone does not show users the interface. Media guidance. No new package release is needed for this listing change. The published version remains unchanged.
Review data
- Reviewed head
5e66daa1151fc4aeec892c4e8197f3407e65e8df, original3122152b55e0ac7afd3aba66ff42e34534ac78fc; main REVIEW.md blob43e9fd13148488473d606daf097c8b27e78ff25a. Read all discussion, prior 0.4.2 outcome and submittedBy attribution; no linked submission issue. - Independently downloaded npm @stevecastaneda/paseo-history 0.4.0 and 0.4.3, verified URLs/versions/SHA-512 against record and npm. 23 old/35 new safe file/directory entries inspected before extraction. New SHA-256
202966770bd939cf93d666bc782ea413ea8e6d6e9e132268e76e487ab9d6516b; oldc9a65cbff00794478467244ab94a30e37662dea6ec8b4f83d3cd47a7dda958cb. Independent complete artifact diff saved; no GitHub source comparison required. - New package bundles marked 17.0.1 and moves type-only @getpaseo/client to development dependencies/host SDK type imports. Removed npm preparation and shrinkwrap; no dependency resolution needed for bundled runtime. Downloaded public marked 17.0.1 tarball and byte-compared its complete tree with bundled marked: identical. No lifecycle scripts. Development/test scripts not invoked. Third-party parser internals not exhaustively audited.
- Read entrypoints, provider/session dispatch, complete file discovery/pagination, OpenCode export and markdown renderer/link handling.
server/history.ts:10–29derives session ID from a known agent, reads only matching provider log roots configured by CODEX_HOME/CLAUDE_CONFIG_DIR.server/files.ts:10–36validates native ID and bounds traversal, rejects ambiguous logs and does not follow directory symlinks. Logs are read only and returned to the connected client; no plugin network requests. Local mutation races in unchanged log reading were not exercised. server/opencode.ts:10–25uses execFile argument arrayopencode export <validated-session-id> --pure, timeout 30 seconds/64 MiB cap, no shell/model command. Overview discloses that execution. Markdown tokenization never injects HTML; images remain links; HTTP(S) links open only on tap, others copy to clipboard.- Author OVERVIEW.md correctly replaces registry fallback. Effective listing.media is empty; package/README/PR and current repository History directory supply no interface image. Added pinned existing icon; validator passes but does not enforce this visual acceptance requirement. Trusted current-main validation passes, registry tests 127/127. No plugin/dependency code installed, built, imported or run. Requested changes, no approval/merge.
The plugin store won't publish History 0.4.3 until the listing shows the History window (getpaseo/plugins#294). The README now has three screenshots: the Conversation view, a turn's Tools tag and the Source view. The main README shows the Conversation view. The README called the second tab "Raw source". The app labels it "Source", so the README does too.
|
Screenshots of the History window, pinned to the commit that added them. Please add them to
|
There was a problem hiding this comment.
History 0.4.3 is approved and merged, @stevecastaneda. I added your three screenshots in the requested order; your shipped overview remains the listing page. Nothing else is needed from you.
Review data
- Reviewed registry head:
5e9b9ef9ce6172eee28247f342b1a269a2bc4937; incoming head:5e66daa1151fc4aeec892c4e8197f3407e65e8df. Current main REVIEW.md blob:43e9fd13148488473d606daf097c8b27e78ff25a. Read all PR comments/reviews and the supplied screenshot reply. Recorded submittedBy and npm package attribution identify the human author; no linked registry submission issue was found. - Independently downloaded and compared npm
@stevecastaneda/paseo-history0.4.0 and 0.4.3. Both versions, tarball URLs and SHA-512 values match their records and npm metadata. New integrity:sha512-uqx0j7Yf9RpxYycME0/N1NKEWOAEjri+Ztb8qcUuGQ25rFOk2mW59IhVGiTN0+IMmp4e98VDcx7eejbNqdJTzw==; archive SHA-256:202966770bd939cf93d666bc782ea413ea8e6d6e9e132268e76e487ab9d6516b. Checked all 23 old/35 new archive entries before confined extraction: regular files/directories, no links or path escapes. - Complete independent delta inspected: documentation/overview, manifest, package metadata, two client type imports, bundled Marked and removed shrinkwrap/preparation. Runtime log discovery/export/rendering source is unchanged. Read server entrypoint, all three server modules, RPC schema, changed client files and Markdown handling; prior published review supplies supporting inspection of unchanged UI. Package identity and entry files match.
- Marked 17.0.1 is bundled, has no runtime dependencies, and all 12 bundled files byte-match its independently downloaded public npm tarball after integrity verification. Other package dependencies are development-only, and runtime SDK/React/zod imports use host libraries. No dependency installation, preparation or lifecycle command is required. Third-party parser internals were not exhaustively audited. No plugin/dependency code installed, built, imported or run.
- Opening History resolves the selected known agent’s native session ID, reads matching Codex/Claude log directories, and returns log contents to the connected client (
server/history.ts:10–29). File discovery validates IDs, bounds traversal and refuses ambiguous matches (server/files.ts:10–36); it does not follow directory symlinks. Existing local file mutation races were not exercised. OpenCode export uses an argument array, validated session ID, 30-second timeout and 64 MiB limit, without a shell (server/opencode.ts:10–25). No plugin network request or filesystem write was found in those paths. - Markdown is tokenized and rendered as UI text, never injected HTML. Images stay labeled links; HTTP(S) links open on user activation and other destinations are copied. The supplied overview accurately explains log access, OpenCode execution and refresh/provider limitations.
- Listing edits: added the three commit-pinned HTTPS PNG URLs and refreshed reviewedAt. All three returned image/png and were visually inspected: sample conversation, tool tags and source view, suitable for the interface. Existing icon retained. Author overview correctly replaces the removed registry fallback.
- Trusted current-main online validation passes on the completed committed proposal: 233 well-formed records, one changed pinned artifact matched. Required PR Validate check passed on this head, including registry tests and record checks. No live plugin, account, browser or daemon QA performed.
stevecastaneda/history: 0.4.0 → 0.4.3
@stevecastaneda, this update is ready for review. The published version stays unchanged until approval.
Artifact and validation details
Package:
@stevecastaneda/paseo-history.{ "previous": { "kind": "npm", "package": "@stevecastaneda/paseo-history", "version": "0.4.0", "resolved": "https://registry.npmjs.org/@stevecastaneda/paseo-history/-/paseo-history-0.4.0.tgz", "integrity": "sha512-j/2/immzCsmbxwZ90LuijvT9wgq0Hq2jDeFKGliOn6gZgkhRiP16aj60jW3xu6ZcNk791NxrMrnWEUBnErL8LQ==" }, "proposed": { "kind": "npm", "package": "@stevecastaneda/paseo-history", "version": "0.4.3", "resolved": "https://registry.npmjs.org/@stevecastaneda/paseo-history/-/paseo-history-0.4.3.tgz", "integrity": "sha512-uqx0j7Yf9RpxYycME0/N1NKEWOAEjri+Ztb8qcUuGQ25rFOk2mW59IhVGiTN0+IMmp4e98VDcx7eejbNqdJTzw==" } }This version ships OVERVIEW.md, so the registry's copy is removed in this bump.
Inline validation passed: tests and artifact checks. Run
node scripts/validate.ts --online --changedon the completed listing before merging. The default GITHUB_TOKEN does not trigger the PR validation workflow.Artifact diff (truncated)
-Or from GitHub:
paseo plugin add stevecastaneda/paseo-plugins --path history.+Or from Paseo's plugin registry:
paseo plugin add stevecastaneda/history.Local install
@@ -39,3 +41,18 @@