Repository navigation
fix(bundler): fix v3 webpackbar bug due to webpack breaking change - #11981
Merged
slorber merged 5 commits intoApr 30, 2026
Merged
Conversation
⚡️ Lighthouse report for the deploy preview of this PR
|
|
Size Change: 0 B Total Size: 12 MB ℹ️ View Unchanged
|
|
Size Change: 0 B Total Size: 12.4 MB ℹ️ View Unchanged
|
✅ [V2]
To edit notification comments on pull requests, go to your Netlify project configuration. |
6 of 7 tasks
This was referenced Apr 30, 2026
1 task
Merged
2 of 3 tasks
sserrata
added a commit
to PaloAltoNetworks/docusaurus-openapi-docs
that referenced
this pull request
May 1, 2026
Patch upgrade for the demo and the create-docusaurus-openapi-docs default template. Picks up the upstream webpackbar/webpack bundler fix from facebook/docusaurus#11981. yarn.lock deduplicated so all @docusaurus/* packages resolve to a single 3.10.1 set.
tylere
added a commit
to source-cooperative/docs.source.coop
that referenced
this pull request
May 8, 2026
Docusaurus 3.10.1 includes facebook/docusaurus#11981, which fixes the webpackbar/webpack 5.99+ ProgressPlugin incompatibility, so the resolutions/overrides pin on webpack 5.97.1 is no longer needed. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>
This was referenced May 12, 2026
Closed
Closed
pull Bot
pushed a commit
to dwongdev/actual
that referenced
this pull request
Jun 1, 2026
* [AI] Fix docs build by pinning webpackbar to v7 webpack 5.106+ removed deprecated ProgressPlugin options, which breaks the older webpackbar 6.0.1 that Docusaurus 3.10.0 depends on. The build fails with "Progress Plugin has been initialized using an options object that does not match the API schema" (unknown properties name/color/ reporters/reporter). Add a webpackbar ^7.0.0 resolution, matching the upstream fix in Docusaurus 3.10.1 (facebook/docusaurus#11981). * Add release notes for PR actualbudget#8018 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
3 of 4 tasks
mbreslow
pushed a commit
to mbreslow/actual
that referenced
this pull request
Jun 8, 2026
* [AI] Fix docs build by pinning webpackbar to v7 webpack 5.106+ removed deprecated ProgressPlugin options, which breaks the older webpackbar 6.0.1 that Docusaurus 3.10.0 depends on. The build fails with "Progress Plugin has been initialized using an options object that does not match the API schema" (unknown properties name/color/ reporters/reporter). Add a webpackbar ^7.0.0 resolution, matching the upstream fix in Docusaurus 3.10.1 (facebook/docusaurus#11981). * Add release notes for PR actualbudget#8018 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
alexqzd
pushed a commit
to alexqzd/actual
that referenced
this pull request
Jul 4, 2026
* :wrench: Prevent release branch workflow from running on forks (#7949) * prevent release branch worfklow from running on forks * release notes * automation UI: add per-category notes and tooltip (#7906) * add per-automation note * add tooltip to automation button * note * tweak placeholder * popover placement * tooltip styling * [AI] Fix split double-counting in balance forecast (#7955) * [AI] Fix split double-counting in balance forecast * [AI] Add release note for forecast split fix * [AI] Move UserDirectoryPage to admin directory (#7951) * [AI] Fix ineffective dynamic import of responsive/wide UserDirectoryPage was statically imported from ./responsive/wide in FinancesApp.tsx, which prevented the bundler from splitting the wide chunk into its own bundle (since responsive/index.tsx dynamically imports it). Import UserDirectoryPage directly from its source so the dynamic import in responsive/index.tsx can move the module into the expected chunk. * [AI] Add release note for #7951 --------- Co-authored-by: Claude <[email protected]> * only count PRs based on master towards maintainer points (#7958) * only count PRs to master * note * [AI] Add blog post announcing no-advertising Discord rule (#7914) * [AI] Add blog post announcing no-advertising Discord rule https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 * [AI] Rewrite no-advertising Discord blog post in maintainer voice https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 * [AI] Quote blog front matter description to fix YAML parse error https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 * [AI] Hyphenate "privacy-oriented" compound adjective in blog post https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 * [AI] Reword advertising policy scope per review feedback https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 --------- Co-authored-by: Claude <[email protected]> * Add stacked net worth docs (#7948) Add some information regarding how to use the stacked net worth report. * move crossover report docs out of experimental (#7953) * move crossover report docs out of experimental * coderabbit * Trim schedule names on save (#7959) * [AI] Trim schedule names on save * [AI] Rename release note for PR number * [AI] Fix last zizmor issues (#7975) * [AI] Address zizmor findings on workflows Replace actions-ecosystem/action-add-labels and action-remove-labels with `gh` CLI calls (superfluous-actions). Silence the six dangerous-triggers findings on pull_request_target/workflow_run workflows with inline `# zizmor: ignore[dangerous-triggers]` and a short rationale — each workflow already follows GitHub's documented safe pattern (no PR code checkout, or validated artifacts only). * [AI] Add release note for zizmor workflow fixes --------- Co-authored-by: Claude <[email protected]> * [AI] Add Claude Code skills for docs, commits, and PR review (#7967) * [AI] Add Claude Code skills for docs, commits, and PR review Add three project-scoped skills under .claude/skills/ so any contributor using Claude Code in this repo gets the same conventions applied automatically: writing-actual-docs (points Claude at writing-docs.md before any docs work), committing-actual-changes (points Claude at pr-and-commit-rules.md before any commit/PR so the [AI] prefix and template-blank rule are followed), and review-actual-pr (end-to-end offline PR review with browser testing via playwright-cli, never posts to GitHub). All skill paths and tool assumptions are repo-relative (resolved via git rev-parse --show-toplevel) so they work on any contributor's machine, not just the author's. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Fix remaining hardcoded $HOME path in PR-review playbook The Step 3 highlight-overlay example still referenced $HOME/.claude/skills/review-actual-pr/... which only resolves on the original author's machine. Switch to the same git rev-parse --show-toplevel pattern used elsewhere in the skill so it works for any contributor with a checkout of the repo. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Add release note for #7967 Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Drop "add AI generated label" instruction now that it auto-applies The "AI generated" PR label is now applied automatically by GitHub Actions to any PR whose title starts with [AI], so the manual "add this label" instruction is stale. It was also misleading for outside contributors, who cannot apply labels on PRs against this repo regardless. Updated the canonical rules file, the committing-actual-changes skill, and the review-actual-pr code-review rubric to describe the prefix as the single trigger and note that the label follows automatically. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * Update Claude Code skills description Simplified the description of Claude Code skills. * [AI] Allow cat and mv in PR-review skill's tool allowlist The workflow saves the final report via `cat > review.md <<'EOF'` (step 6) and rotates a stale prior report via `mv` (step 2, re-runs), but the allowed-tools line did not permit either, so those commands would prompt or fail at runtime. Add Bash(cat:*) and Bash(mv:*) — keeping the allowlist tight rather than broadening to Bash(*), so unrelated shell commands still require explicit authorization. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> --------- Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> * [Docs] UI Budget automations & month-end cleanup (#7863) * Add files via upload * Create documentation for budget automation feature Added documentation for the budget automation feature, detailing its functionalities, usage, and examples. * Add files via upload * Revise budget automation documentation for clarity Updated the documentation for budget automation, enhancing clarity and consistency in the descriptions of features and options. * [autofix.ci] apply automated fixes * Update Markdown headers for budget automation section * Add files via upload * Improve formatting in budget automation documentation Updated formatting and added line breaks for better readability in the budget automation documentation. * [autofix.ci] apply automated fixes * Fix HTML line breaks in budget-automation.md Updated HTML line breaks from '</br>' to '<br>' in budget automation documentation. * Fix HTML line breaks in budget automation documentation * Fix headings and formatting in budget-automation.md Updated formatting and corrected headings in budget automation documentation. * Add budget-automation to sidebar items * Add files via upload * Add files via upload * Revise budget automation documentation Updated budget automation documentation to clarify usage of notes templates and detailed instructions for month-end cleanup processes, including named pools and weight calculations. * [autofix.ci] apply automated fixes * Refactor budget automation documentation for clarity Updated various sections for clarity and consistency, including grammar corrections and improved phrasing. * [autofix.ci] apply automated fixes * Enhance budget automation documentation Updated budget automation documentation with new blog links and improved formatting. * Fix links in budget-automation.md Updated links in the budget automation documentation to remove 'docs' prefix for consistency. * Revise budget automation documentation with updates Updated images and text for budget automation documentation, including corrections and enhancements to clarity. * Improve clarity and add save reminders in budget automation Updated wording for clarity and added reminders for saving work. * Update budget automation documentation for clarity Clarify the process of handling leftover funds in the budget automation script. * [autofix.ci] apply automated fixes * Add 'overfund' and 'overfunded' to spelling expect list * Update spelling expectations by removing 'overfunded' Removed 'overfunded' from the spelling expectations. * Add files via upload * 'overfund' to 'overfunded' First the bot tells me overfunded isn't needed if overfund is there. Now, it tells me that overfunded IS needed. I give up. * Enhance budget automation documentation Added new sections on automation adjustments, moved some sections around, added horizontal separators. * Update images and descriptions in budget automation docs * Add files via upload * Add automation notes section to budget automation docs Added a section on automation notes to document how automations, balance caps, and long-term goals can have associated notes for clarity and tracking. * Add files via upload * Update budget automation examples in documentation * Add files via upload * Apply suggestions from code review Co-authored-by: Matt Fiddaman <[email protected]> * [autofix.ci] apply automated fixes * Add 'unmigrate' to spelling expectations * Improve clarity in budget automation documentation Clarified descriptions for budget automation features and improved wording for better understanding. * Correct spelling of 'unmigrate' to 'Unmigrate' They are the same and github is punking me again. * Clarify automation notes description * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Fix typos in budget-automation documentation Corrected typos and improved clarity in the budget automation documentation. --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> * Bump the npm_and_yarn group across 1 directory with 3 updates (#7980) Bumps the npm_and_yarn group with 3 updates in the / directory: [ip-address](https://github.com/beaugunderson/ip-address), [tmp](https://github.com/raszi/node-tmp) and [webpack](https://github.com/webpack/webpack). Updates `ip-address` from 10.0.1 to 10.1.0 - [Commits](https://github.com/beaugunderson/ip-address/compare/v10.0.1...v10.1.0) Updates `tmp` from 0.2.5 to 0.2.7 - [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md) - [Commits](https://github.com/raszi/node-tmp/compare/v0.2.5...v0.2.7) Updates `webpack` from 5.102.1 to 5.107.2 - [Release notes](https://github.com/webpack/webpack/releases) - [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md) - [Commits](https://github.com/webpack/webpack/compare/v5.102.1...v5.107.2) --- updated-dependencies: - dependency-name: ip-address dependency-version: 10.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tmp dependency-version: 0.2.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: webpack dependency-version: 5.107.2 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * [AI] Upgrade dependencies to resolve security advisories (#7982) * [AI] Upgrade dependencies to resolve security advisories Resolve 9 Dependabot security alerts via version upgrades: - rollup: remove the resolutions pin that forced workbox-build's rollup ^2.79.2 up to vulnerable 4.40.1; it now resolves to the patched 2.80.0 (vite 8 uses rolldown, so no rollup 4.x is needed) (CVE-2026-27606) - serialize-javascript: add resolution ^7.0.5 (build-time only; consumers are deep-transitive webpack/terser plugins pinned to ^6) (GHSA-5c6j-r48x-rmvq, CVE-2026-34043) - express-rate-limit ^8.3.2 -> ^8.5.2, pulling ip-address 10.2.0 (CVE-2026-42338) - refresh in-range transitives: bn.js 5.2.3, ajv 8.20.0, glob 10.5.0, path-to-regexp 8.4.2 (CVE-2026-2739, CVE-2025-69873, CVE-2025-64756, CVE-2026-4926, CVE-2026-4923) Not addressed: elliptic (CVE-2025-14505) has no patched release; uuid 8.3.2 (dev-only via sockjs, not reachable) left as-is. https://claude.ai/code/session_018obbND7t9dBZvfvUBBJKFz * [AI] Remove redundant minimatch resolution pins Five of the six minimatch resolutions were no-ops: their consumers use caret ranges (^3.x, ^5.x, ^9.x, ^10.x) that already float to versions patched against CVE-2026-26996 (3.1.5, 5.1.9, 9.0.9, 10.2.5). Only serve-handler pins minimatch to exactly 3.1.2 (vulnerable), so the single targeted "[email protected]" override is kept. The resolved lockfile is unchanged. https://claude.ai/code/session_018obbND7t9dBZvfvUBBJKFz * Add release notes for PR #7982 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Fix fatal error when launching PWA while offline (#7978) * [AI] Fix fatal error when launching PWA while offline (#7886) The Vite migration in 26.5 changed how `data-file-index.txt` is generated. The previous shell-based `cp ... migrations/*` and `find * -type f` skipped dotfiles by default, but the new `fs.cp`/`fs.readdir` recursive calls include them. As a result the legacy `.force-copy-windows` marker file ended up in the index and the app fetched it on every startup. The workbox precache globs only match files with known extensions, so this dotfile is never cached; opening the PWA offline therefore failed the entire `populateDefaultFilesystem` step and rendered a fatal error. Skip dotfiles when generating the index (restoring the pre-26.5 behavior) and remove the stale marker file. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * Add release notes for PR #7978 * Delete upcoming-release-notes/7886.md --------- Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Revert "[AI] chore: update alpine base image to 3.23.4" (#7985) * Revert "[AI] chore: update alpine base image to 3.23.4 (#7939)" This reverts commit 366045a6b071e431f4afe7aef6a7fd1a0af15245. * Add release notes for PR #7985 * Delete upcoming-release-notes/7985.md --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Fix small visual issues on mobile transaction entry (#7962) * [AI] Fix small visual issues on mobile transaction entry - Left-align text in the date field (was centered on mobile browsers). - Show focus border on the whole icon-prefixed field (date, notes) instead of only under the input, and drop the rounded corners that leaked through from the inner Input's box-shadow. - Balance focused vs unfocused borders on the amount field so the page no longer shifts down by 1px when it gains focus. * [AI] Left-align mobile date field via WebKit pseudo-element iOS/WebKit renders <input type="date"> text inside the ::-webkit-date-and-time-value pseudo-element, which ignores the input's own text-align. Target the pseudo-element directly. * Add release notes for PR #7962 * [AI] Prevent icon shift when disabling mobile transaction fields When the disabled state of a mobile transaction field changed, the icon could drift up by 1px. Two contributing factors: - The wrapper's emotion class was regenerated when disabled toggled (because backgroundColor was baked into it). Moving the background to an inline style keeps the wrapper's className constant. - The icon was a flex item with intrinsic height being centered by the wrapper in an even-pixel content area, which is a half-pixel centering that can round inconsistently across re-layouts. Stretch the icon container to the full wrapper height and center the SVG internally so the icon's final position no longer depends on the wrapper recalculating cross-axis offsets. * Update VRT screenshots Auto-generated by VRT workflow PR: #7962 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Restrict owner-only sync-server file management endpoints (#7977) * [AI] Restrict owner-only sync-server file management endpoints The /delete-user-file, /reset-user-file, and /user-create-key endpoints guarded access via requireFileAccess, which accepted any user holding a user_access row. A shared collaborator could therefore mark another owner's hosted budget file as deleted, reset its sync state, or rewrite its encryption key. Add a stricter requireFileOwner helper (owner or server admin only) and apply it to the three management endpoints. requireFileAccess keeps its shared-access fallback for the collaboration endpoints (sync, upload, download, get/update filename, get/create encryption key consumers). Fixes GHSA-23vm-ffgg-qvjr. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Align release-note filename with PR number Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * Update release notes for sync-server endpoint restrictions Clarified the restriction on sync-server endpoints to only allow file owners and admins to perform owner-only file-management actions. * Update upcoming-release-notes/7977.md Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * :iphone: Fallback to direct worker on ios (#7971) * fallback to old worker on ios * release note * Correct spelling of 'iOS' in release notes * Improve Tag Filter UX (#7848) * [AI] Make TypeScript work in test files across packages Match the CRDT package's tsconfig pattern in loot-core, desktop-client, api, and desktop-electron so test files participate in the project graph (IDE intellisense, project-wide typecheck) while production builds still emit clean declaration files. - Remove test-file exclusions from each package's main tsconfig - Add tsconfig.build.json for loot-core and api with test exclusions, used by the build scripts - Add e2e/tsconfig.json for desktop-client and desktop-electron with Playwright types - Fix latent type errors in test files now caught by typecheck - Disable typescript/unbound-method for test files (mock matcher pattern) Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Address review feedback on test type fixes - goal-template.test.ts: extract amounts to typed locals so single-value assertions no longer compare against unknown - category-template-context.test.ts: replace `as unknown as DbCategory` double-cast with a fully-typed object using `satisfies DbCategory` (the previous mock had `is_income: true` which doesn't match the `1 | 0` shape the cast was hiding) - api/tsconfig.build.json: broaden test exclude pattern to `**/*.test.ts` Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Drop tsconfig.build.json for loot-core and api The build-config indirection was incomplete protection: typecheck (`tsgo -b` against the main tsconfig, which now includes test files) already emits `*.test.d.ts` into `@types/`, and the build step does not clean before re-emitting. The same is observable in crdt's `dist/`, which currently contains test declarations on disk. What actually keeps test declarations out of the npm tarball is the `files` field in package.json — and loot-core already uses that mechanism for source files (`\!src/**/*.test.ts`). Extending the same pattern to `@types/` is more direct than maintaining a duplicate tsconfig that doesn't reliably do its job. - Delete loot-core/tsconfig.build.json; revert build to `tsgo -b`; add `\!@types/**/*.test.d.ts*`, `\!@types/**/__tests__/**`, `\!@types/**/__mocks__/**` to `files`. - Delete api/tsconfig.build.json; revert build to `vite build && tsgo --emitDeclarationOnly`; add `\!@types/**/*.test.d.ts*` to `files`. Verified: `yarn pack --dry-run` excludes all test declarations from both packages while production declarations still pack (428 .d.ts files for loot-core, methods.d.ts for api). Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * first pass at implementation * finished implementing what I feel would be a good user experience * padding update * added ability to use tab to select * release notes * updated release notes * auto highlights first entry * removed debug info * linting formatting * updated behavior with tags in the middle of stuff * minor improvements to ux * extracted TagAutocomplete functionality into its own file * rewrote TagAutocomplete using react-aria-components from scratch * linting * restored old autocomplete since I'm no longer using it * linting * capped results at 10 * bugfix * used tag css hook instead of notes tag formatter * added mobile support * fixed bug where inserting a tag at the end of the note wouldn't fire onChange handler * fixed bug where note would hover even though field was not focused * fixed bug with currentWord detection * some more minor UI bugs with the mobile UI * removed log statement * added aria-label * [autofix.ci] apply automated fixes * name to Input * updatedt ests * fixed tests * whitespace adjustment * removed debug from test * added tests and made a few fixes * tried to fix vrt * some new hooks to use * removed log statement * removed input from useCursorPosition * input ref value hook now triggers on mount * add extra padding * hide browser autocomplete when our popup is shown to avoid doubles * useFilteredTags hook and adjustments to mobile tag UI * switched from opacity to height transitioning * sorted filtered tags by startsWith first * updated highlighting logic for mouseover * [autofix.ci] apply automated fixes * fix tag ordering * button type * [autofix.ci] apply automated fixes * release note update * release note to trigger ci * reverted db change * Revert "reverted db change" This reverts commit 24ce5450e5e4261e77fe5056620c240da22869a3. * can now filter by tags without hashes * extracted a method and added a new hasAnyTags rule * added hasAnyTag, still need to figure out why tests are failing * fixed unit tests * release notes * fixed based on coderabbit * tag.toLowerCase() * variable scope fix * fixed some focus-related bugs * allow creating tags in the dropdown for desktop * fixed focus issues with useCursorPosition * added Create Tag functionality to mobile * tests and added some length clipping as qol * can now use enter to submit new tag properly * centralized overflow CSS for tags * centered the text horizontally * added textnowrap * release notes * linting * fixed issue with async keydown handler * specified only to use new tag css for the autocomplete stuff * forgot to add new option to tag table * removed Trans * started working on multiselect * multiselect is now functional * finished multiAutocomplete implementation * [autofix.ci] apply automated fixes * removed double input * added multi autocomplete to rule editor * adjusted padding for TagMultiAutocomplete * adjusted hover cursor * release notes * fixed rule conditions * added tag styling to filter multiselect * spacing adjustment * release notes for retriggering build --------- Co-authored-by: github-actions[bot] <[email protected]> Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: Alec Bakholdin <alecbakholdin.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * Add Iranian Rial (#7945) * Add Iranian Rial * Rename file so Ci passes * [AI] Use fixed version for Playwright tests (#7965) * [AI] Pin Electron Playwright version to 99.9.9 The version number at the bottom of the Management page is sourced from package.json via app.getVersion(), so each release rotates the dynamic version string in VRT screenshots. The browser bundle already swaps in a static '99.9.9' for Playwright (browser-preload.js); mirror that in the Electron bootstrap data so desktop VRT snapshots don't break on version bumps. Existing snapshots need to be regenerated once (via /update-vrt on the PR) since they were captured with the live package.json version. * Update VRT screenshots Auto-generated by VRT workflow PR: #7965 * [AI] Pin Playwright server version to 99.9.9 The Management page footer also renders the sync server version, which 'get-server-version' fetches from the sync-server's /info endpoint (its own package.json). Short-circuit getServerVersion() to '99.9.9' when running under Playwright so VRT snapshots stay stable across releases. * Update VRT screenshots Auto-generated by VRT workflow PR: #7965 * [AI] Set 'playwright' userAgent on Electron BrowserWindow under Playwright playwright.config.ts only sets userAgent for direct chromium launches — _electron.launch() leaves the BrowserWindow with Chromium's default UA, so Platform.isPlaywright (which checks navigator.userAgent) is false in the renderer. That's why the ServerContext shortcut wasn't pinning the server version for desktop VRT snapshots. Force the UA on the webContents when EXECUTION_CONTEXT=playwright so renderer-side Playwright checks light up. * Update VRT screenshots Auto-generated by VRT workflow PR: #7965 * [AI] Preserve Electron substring in Playwright userAgent Replacing the Electron renderer's UA with bare 'playwright' broke environment.isElectron() (it greps for 'Electron' in navigator.userAgent), which rerouted ConfigServer.tsx into the external-server branch — the sync-server e2e test could no longer find the Start button to navigate to the bootstrap page, so its snapshot kept falling through every /update-vrt unchanged. Append ' playwright' to the existing Electron UA instead, and widen the Platform.isPlaywright check to a substring match so both 'playwright' (chromium tests) and 'Electron/… playwright' (electron tests) resolve to true. * Update VRT screenshots Auto-generated by VRT workflow PR: #7965 * Add release notes for PR #7965 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] New chip on payee field now surfaces a lack of geolocation permissions (#7883) * New chip on payee field now surfaces a lack of geolocation permissions * Addressing coderabbit feedback * Update category in release notes for transaction editing Changed category from Maintenance to Enhancements for clarity. --------- Co-authored-by: Matiss Janis Aboltins <[email protected]> * fix schedule modal scrollbars (#7992) * [AI] Custom highlight for added sync items: transaction table and sidebar (#7998) * Add new CSS variables for text items in dark theme * Add new CSS variables for table and sidebar items * Add new CSS variables for table and sidebar items * Update sidebar account style for updated state * Enhance valueStyle with color for added items * [autofix.ci] apply automated fixes * Add new theme variables for table and sidebar * Add color variables to added sync items Add color variables for enhanced visibility of items. * [AI] Apply added-row styling to transaction notes cell Co-authored-by: Cursor <[email protected]> --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Cursor <[email protected]> * Add Pakistani PKR currency (#7993) Co-authored-by: Awais Saeed <[email protected]> * add trend line to line graphs (#7954) * add trend line to line graphs * note * add to options * split trend generation logic into seperate handler, add test * tighten types * Goal Templates keyboard shortcut (#7912) * add shortcut * note * change shortcut to ctrl-t * shift t * [AI] Add npm minimal age gate for supply-chain defense (#8011) * [AI] Add npmMinimalAgeGate to block dependency versions newer than 3 days * [autofix.ci] apply automated fixes * [AI] Add release notes for npm minimal age gate --------- Co-authored-by: Claude <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * Add initial docs for Enable Banking (#7961) * Add initial docs for Enable Banking * Delete upcoming-release-notes/7961.md * [AI] Fix docusaurus docs build (#8018) * [AI] Fix docs build by pinning webpackbar to v7 webpack 5.106+ removed deprecated ProgressPlugin options, which breaks the older webpackbar 6.0.1 that Docusaurus 3.10.0 depends on. The build fails with "Progress Plugin has been initialized using an options object that does not match the API schema" (unknown properties name/color/ reporters/reporter). Add a webpackbar ^7.0.0 resolution, matching the upstream fix in Docusaurus 3.10.1 (facebook/docusaurus#11981). * Add release notes for PR #8018 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * add EB docs to sidebar (#8019) * 🔖 (26.6.0) (#7947) * 🔖 (26.6.0) * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * Update check-spelling metadata * Generate release notes for v26.6.0 * add release summary * links * Generate release notes for v26.6.0 * update links * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * add EB link * Add initial docs for Enable Banking (#7961) * Add initial docs for Enable Banking * Delete upcoming-release-notes/7961.md * [Docs] UI Budget automations & month-end cleanup (#7863) * Add files via upload * Create documentation for budget automation feature Added documentation for the budget automation feature, detailing its functionalities, usage, and examples. * Add files via upload * Revise budget automation documentation for clarity Updated the documentation for budget automation, enhancing clarity and consistency in the descriptions of features and options. * [autofix.ci] apply automated fixes * Update Markdown headers for budget automation section * Add files via upload * Improve formatting in budget automation documentation Updated formatting and added line breaks for better readability in the budget automation documentation. * [autofix.ci] apply automated fixes * Fix HTML line breaks in budget-automation.md Updated HTML line breaks from '</br>' to '<br>' in budget automation documentation. * Fix HTML line breaks in budget automation documentation * Fix headings and formatting in budget-automation.md Updated formatting and corrected headings in budget automation documentation. * Add budget-automation to sidebar items * Add files via upload * Add files via upload * Revise budget automation documentation Updated budget automation documentation to clarify usage of notes templates and detailed instructions for month-end cleanup processes, including named pools and weight calculations. * [autofix.ci] apply automated fixes * Refactor budget automation documentation for clarity Updated various sections for clarity and consistency, including grammar corrections and improved phrasing. * [autofix.ci] apply automated fixes * Enhance budget automation documentation Updated budget automation documentation with new blog links and improved formatting. * Fix links in budget-automation.md Updated links in the budget automation documentation to remove 'docs' prefix for consistency. * Revise budget automation documentation with updates Updated images and text for budget automation documentation, including corrections and enhancements to clarity. * Improve clarity and add save reminders in budget automation Updated wording for clarity and added reminders for saving work. * Update budget automation documentation for clarity Clarify the process of handling leftover funds in the budget automation script. * [autofix.ci] apply automated fixes * Add 'overfund' and 'overfunded' to spelling expect list * Update spelling expectations by removing 'overfunded' Removed 'overfunded' from the spelling expectations. * Add files via upload * 'overfund' to 'overfunded' First the bot tells me overfunded isn't needed if overfund is there. Now, it tells me that overfunded IS needed. I give up. * Enhance budget automation documentation Added new sections on automation adjustments, moved some sections around, added horizontal separators. * Update images and descriptions in budget automation docs * Add files via upload * Add automation notes section to budget automation docs Added a section on automation notes to document how automations, balance caps, and long-term goals can have associated notes for clarity and tracking. * Add files via upload * Update budget automation examples in documentation * Add files via upload * Apply suggestions from code review Co-authored-by: Matt Fiddaman <[email protected]> * [autofix.ci] apply automated fixes * Add 'unmigrate' to spelling expectations * Improve clarity in budget automation documentation Clarified descriptions for budget automation features and improved wording for better understanding. * Correct spelling of 'unmigrate' to 'Unmigrate' They are the same and github is punking me again. * Clarify automation notes description * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Fix typos in budget-automation documentation Corrected typos and improved clarity in the budget automation documentation. --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: github-merge-queue <[email protected]> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> Co-authored-by: Mats Nilsson <[email protected]> Co-authored-by: Juulz <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Improve Balance Forecast captions (#7957) * [AI] Add visible low point helper for forecasts * [AI] Show ending balance in forecast report * [AI] Show ending balance on forecast card * [AI] Update balance forecast report snapshots * [AI] Add release note for forecast captions * [AI] API: improve messaging for version/schema mismatch errors (#8026) * [AI] Improve messaging for API version/schema mismatch errors When an outdated client or @actual-app/api connects to a budget whose data uses a newer database schema, sync-apply fails with a cryptic "no such column" error that surfaced as a generic download/sync error. Add a version-mismatch message in getDownloadError/getSyncError, gated on the actual SQLite schema-error signature (no such column/table) so other invalid-schema failures keep their generic messaging and otherwise compatible API versions remain usable. * [AI] Set release note author to MatissJanis * Add release notes for PR #8026 * [AI] Address review: use Vitest globals and remove duplicate release note - Drop the explicit `vitest` import in errors.test.ts and rely on the configured test globals (per CodeRabbit review). - Remove the duplicate 8021.md release note, keeping the PR-numbered 8026.md with the clearer description. * [AI] Avoid i18n in loot-core for schema-mismatch message Return the schema-mismatch error as a plain string instead of going through i18next, and drop the i18next setup from the test. loot-core does not depend on i18n, and this message is surfaced verbatim through the programmatic API. * [AI] Remove unnecessary code comments * [AI] Add missing-meta test for getDownloadError --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Fix typo in Budget Automation math expression (#8035) * Fix typo in Budget Automation math expression * Remove release note --------- Co-authored-by: youngcw <[email protected]> * [AI] docs: update reset-password instructions (#7950) * [AI] docs: update reset-password instructions Clarify the current host-side command and keep the source-checkout workflow documented. Closes #7943 * [AI] docs: keep npm reset path alongside actual-server * Fix CSV import settings reset when skipping end lines (#7827) * [AI] fix(api): prevent navigator crash when loading @actual-app/api in Node.js (#8037) * [AI] fix(api): prevent navigator crash when loading @actual-app/api in Node.js Problem ------- @actual-app/api 26.5.0 and 26.6.0 throw "ReferenceError: navigator is not defined" on import in Node.js environments. The loot-core shared bundle includes three platform variants: platform.ts – browser (references navigator at module load time) platform.electron.ts – Electron/desktop (uses Node.js os module) platform.api.ts – Node.js API (safe constants only) The API vite build uses `resolve: { conditions: ['api'] }` to pick the right variant via the loot-core package imports map (#shared/platform). However, months.ts was importing via a bare relative path (`./platform`) instead of the imports-map alias (`#shared/platform`). Vite's conditions-based resolution does not apply to relative imports, so the build fell back to platform.ts (the browser variant), bundling navigator references that crash at load time. Fix --- Change months.ts to import `#shared/platform` instead of `./platform`. This goes through the loot-core package imports map, which the vite `api` condition resolves to platform.api.ts — the Node.js-safe variant. platform.api.ts was already added to the repo alongside this condition infrastructure (in the same 26.6.0 release) but the months.ts import was missed, leaving the crash in the published package. Testing ------- Added packages/api/platform.test.ts, which imports @actual-app/core/shared/ platform under the `api` vite condition and asserts that isBrowser, isPlaywright and isIOSAgent are all false. This test: - Fails if platform.api.ts is deleted (module not found) - Fails if platform.api.ts is modified to reference navigator (ReferenceError) - Fails if the api vite condition is removed, falling back to platform.ts which throws ReferenceError at import time in Node.js Verified by Kyle Slattery against a live Actual Budget instance via the actual-flow integration tool (https://github.com/lunchflow/actual-flow). * Add release note * Update upcoming-release-notes/8037.md Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Delete packages/api/platform.test.ts --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * [AI] Move i18n usage outside of loot-core (#8027) * [AI] Move i18n usage outside of loot-core loot-core should be platform-agnostic and free of i18n concerns. This moves all user-facing translated string helpers (rule/schedule labels, error formatters) into desktop-client's #util/{rule,schedule,error} modules, while keeping the underlying logic in loot-core. - Headless @actual-app/api error formatters in loot-core now return plain English strings (the API has no i18n runtime). - The persisted "Unknown" institution name and the platform storage alert use plain strings. - Removed the unused i18next dependency from loot-core. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Address review feedback on i18n-out-of-loot-core PR - Wrap switch default arms in blocks to satisfy noSwitchDeclarations (desktop-client and loot-core getDownloadError) - getSecretsError: return a localized generic message instead of leaking the raw backend error token - getRecurringDescription: always separate the weekend annotation so it no longer renders as "Monday(after weekend)"; add test coverage - IndexedDB quota error: surface a typed 'indexeddb-quota-error' event from loot-core and present the localized alert in desktop-client instead of a hard-coded English string - Persist a null bank name (instead of English "Unknown") when the provider reports no institution, and render a localized fallback in the bank sync UI --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Fix Balance Forecast chart colors with custom themes (#8031) * [AI] Use report theme colors for Balance Forecast chart lines * [AI] Add release notes for Balance Forecast custom theme fix * fix react compiler on Windows (#8049) * hmm.. * note * [Docs] Revise fly.io deployment instructions for nightly builds (#8059) * Revise deployment instructions for nightly builds Updated instructions for deploying unstable versions of Actual. * Clarify fly deploy commands in installation guide Updated deployment commands for clarity and added example for nightly version. * [autofix.ci] apply automated fixes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Scope Electron update to v41 (#8044) * Initial plan * Bump desktop Electron runtime to v42.3.0 * Add release notes entry for PR #8044 * Change author from Copilot to MikesGlitch Updated author information in release notes. * Update node-abi mappings to support Electron 42 ABI detection * Address validation feedback for Electron update PR * Add better-sqlite3 Electron 42 patch * Update lockfile for better-sqlite3 patch * Remove better-sqlite patch protocol and target Electron 41 * Align release note with Electron 41.7.1 change * Update better-sqlite3 ranges to ^12.8.0 --------- Co-authored-by: copilot-swe-agent[bot] <[email protected]> Co-authored-by: Michael Clark <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * [Enhancements] Removed regex from excel formula execution (#7990) * Removed regex from excel formula execution * [autofix.ci] apply automated fixes * Surface error for BUDGET_QUERY * code review --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Fix balance forecast report Y-axis label clipping (#8030) * [AI] Fix balance forecast report Y-axis label clipping * [AI] Add release notes for #8030 * docs: add actual-bench to community projects (#8045) * docs: add actual-bench to community projects * [autofix.ci] apply automated fixes * docs: add release note for actual-bench community entry * [autofix.ci] apply automated fixes * fix: address coderabbit comments * fix: remove upcoming release notes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Add Sort A to Z / Sort Z to A options to budget category groups (#7831) * [AI] Add Sort A to Z / Sort Z to A options to budget category groups (#7831) * Simplify release notes and apply coderabbitai suggestions * [AI] fix(api): trigger SimpleFin batch sync with a single account (#8052) The condition required more than one SimpleFin account before running batch sync, causing a single SimpleFin account to be skipped entirely. Co-authored-by: Claude Opus 4.6 <[email protected]> * add pikapods desktop warning (#8061) * add pikapods desktop warning * better link * add to spelling list * more spelling * [AI] Fix bug when linking accounts (#8006) Fixes a bug that when selecting Link Account from the account page one has to reselect the same account in the modal even though its prepopulated. Co-authored-by: Gemini <[email protected]> * add MXN peso (#8060) * ♻️ remove unnecessary playwright container pulls to speed up CI (#8067) * don't use playwright where it's not needed * note * [AI] Add auto-generated Upcoming Release docs page (#8065) * [AI] Add auto-generated Upcoming Release docs page Adds a docs page that always reflects the current contents of the repo-root upcoming-release-notes/ directory — the changes that have been merged but not yet published in a stable release (i.e. what ships in the nightly/edge builds). - Extract parseReleaseNotes/formatNotes from the release-notes generator into the shared ci-actions util so both the release generator and the docs build reuse the same formatting. - Add a docs build script that regenerates docs/upcoming-release-notes.md on every start/build, with an intro explaining the notes are unreleased and how to try them, plus the categorized notes list. - Wire the generator into the docs start/build scripts, add a sidebar entry next to Release Notes, and gitignore the generated page. https://claude.ai/code/session_01MuY9Phome8uJKH51HbrsQw * [AI] Simplify upcoming-release-notes generator - Declare @actual-app/ci-actions as a workspace dependency and import the shared util by package name instead of a relative cross-package path, so the dependency is registered in the workspace graph. - Resolve the repo root once via new URL() and drop the dirname import. - Use a ternary for the page body instead of let + if/else. https://claude.ai/code/session_01MuY9Phome8uJKH51HbrsQw * Add release notes for PR #8065 * [AI] Remove edge references, keep only nightly in docs Co-authored-by: Matiss Janis Aboltins <[email protected]> * Update packages/docs/scripts/generate-upcoming-release-notes.mjs Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Cursor Agent <[email protected]> Co-authored-by: Matiss Janis Aboltins <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * Bump the npm_and_yarn group across 2 directories with 1 update (#8071) Bumps the npm_and_yarn group with 1 update in the / directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Bumps the npm_and_yarn group with 1 update in the /packages/desktop-client directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Updates `react-router` from 7.13.1 to 7.14.2 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) Updates `react-router` from 7.13.1 to 7.14.2 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) --- updated-dependencies: - dependency-name: react-router dependency-version: 7.14.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: react-router dependency-version: 7.14.2 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * When resetting SimpleFIN credentials, parse error and error_code if response body exists (#8068) * Initial commit * Add release note * Update release note file name to match PR number * Flip operands when checking for 2xx * Release notes grammar * Better release note for non-devs * Simplify to naive solution of checking on nullable response * Hiding tags and tag table bulk actions (#7919) * [AI] Make TypeScript work in test files across packages Match the CRDT package's tsconfig pattern in loot-core, desktop-client, api, and desktop-electron so test files participate in the project graph (IDE intellisense, project-wide typecheck) while production builds still emit clean declaration files. - Remove test-file exclusions from each package's main tsconfig - Add tsconfig.build.json for loot-core and api with test exclusions, used by the build scripts - Add e2e/tsconfig.json for desktop-client and desktop-electron with Playwright types - Fix latent type errors in test files now caught by typecheck - Disable typescript/unbound-method for test files (mock matcher pattern) Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Address review feedback on test type fixes - goal-template.test.ts: extract amounts to typed locals so single-value assertions no longer compare against unknown - category-template-context.test.ts: replace `as unknown as DbCategory` double-cast with a fully-typed object using `satisfies DbCategory` (the previous mock had `is_income: true` which doesn't match the `1 | 0` shape the cast was hiding) - api/tsconfig.build.json: broaden test exclude pattern to `**/*.test.ts` Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Drop tsconfig.build.json for loot-core and api The build-config indirection was incomplete protection: typecheck (`tsgo -b` against the main tsconfig, which now includes test files) already emits `*.test.d.ts` into `@types/`, and the build step does not clean before re-emitting. The same is observable in crdt's `dist/`, which currently contains test declarations on disk. What actually keeps test declarations out of the npm tarball is the `files` field in package.json — and loot-core already uses that mechanism for source files (`\!src/**/*.test.ts`). Extending the same pattern to `@types/` is more direct than maintaining a duplicate tsconfig that doesn't reliably do its job. - Delete loot-core/tsconfig.build.json; revert build to `tsgo -b`; add `\!@types/**/*.test.d.ts*`, `\!@types/**/__tests__/**`, `\!@types/**/__mocks__/**` to `files`. - Delete api/tsconfig.build.json; revert build to `vite build && tsgo --emitDeclarationOnly`; add `\!@types/**/*.test.d.ts*` to `files`. Verified: `yarn pack --dry-run` excludes all test declarations from both packages while production declarations still pack (428 .d.ts files for loot-core, methods.d.ts for api). Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * first pass at implementation * finished implementing what I feel would be a good user experience * padding update * added ability to use tab to select * release notes * updated release notes * auto highlights first entry * removed debug info * linting formatting * updated behavior with tags in the middle of stuff * minor improvements to ux * extracted TagAutocomplete functionality into its own file * rewrote TagAutocomplete using react-aria-components from scratch * linting * restored old autocomplete since I'm no longer using it * linting * capped results at 10 * bugfix * used tag css hook instead of notes tag formatter * added mobile support * fixed bug where inserting a tag at the end of the note wouldn't fire onChange handler * fixed bug where note would hover even though field was not focused * fixed bug with currentWord detection * some more minor UI bugs with the mobile UI * removed log statement * added aria-label * [autofix.ci] apply automated fixes * name to Input * updatedt ests * fixed tests * whitespace adjustment * removed debug from test * added tests and made a few fixes * tried to fix vrt * some new hooks to use * removed log statement * removed input from useCursorPosition * input ref value hook now triggers on mount * add extra padding * hide browser autocomplete when our popup is shown to avoid doubles * useFilteredTags hook and adjustments to mobile tag UI * switched from opacity to height transitioning * sorted filtered tags by startsWith first * updated highlighting logic for mouseover * [autofix.ci] apply automated fixes * fix tag ordering * button type * [autofix.ci] apply automated fixes * release note update * release note to trigger ci * reverted db change * Revert "reverted db change" This reverts commit 24ce5450e5e4261e77fe5056620c240da22869a3. * can now filter by tags without hashes * extracted a method and added a new hasAnyTags rule * added hasAnyTag, still need to figure out why tests are failing * fixed unit tests * release notes * fixed based on coderabbit * tag.toLowerCase() * variable scope fix * fixed some focus-related bugs * allow creating tags in the dropdown for desktop * fixed focus issues with useCursorPosition * added Create Tag functionality to mobile * tests and added some length clipping as qol * can now use enter to submit new tag properly * centralized overflow CSS for tags * centered the text horizontally * added textnowrap * release notes * linting * fixed issue with async keydown handler * specified only to use new tag css for the autocomplete stuff * forgot to add new option to tag table * removed Trans * started working on multiselect * multiselect is now functional * finished multiAutocomplete implementation * [autofix.ci] apply automated fixes * removed double input * added multi autocomplete to rule editor * adjusted padding for TagMultiAutocomplete * adjusted hover cursor * release notes * fixed rule conditions * added tag styling to filter multiselect * spacing adjustment * release notes for retriggering build * added hidden migration * added hidden to models * added tags-hide-all and tags-unhide-all actions * added hide and unhide tags actions * added SelectedTagsButton * added UI elements for hiding/showing tags * release notes * removed delete from ManageTags * added icons to menu * coderabbit * coderabbit * updated mutations for translations * coderabbit * removed not null requirement * attempted to fix tests? * removed duplicate filterTags * [autofix.ci] apply automated fixes * updated release notes * release note update * updated migration timestamp * moved tags menu button --------- Co-authored-by: github-actions[bot] <[email protected]> Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: Alec Bakholdin <alecbakholdin.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * automation UI: improve scaling (#8080) * improve scaling on high zoom levels * note * automation UI: rework balance cap and fix error when clearing fields (#8082) * fix safeNumber error * rework balance cap UI to be more readable * note * add explanation to balance cap * Bump react-router in the npm_and_yarn group across 1 directory (#8072) Bumps the npm_and_yarn group with 1 update in the / directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Updates `react-router` from 7.14.2 to 7.15.0 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) --- updated-dependencies: - dependency-name: react-router dependency-version: 7.15.0 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * [AI] feat(currencies): add currency-precision-aware helpers (#8064) * [AI] feat(currencies): add getDecimalPlaces/getCurrencyPrecisionMultiplier helpers, encodeAmount, currency-aware integerToCurrencyWithDecimal * Fix typo in release note * Use it.each in unit tests * Rename encodeAmount and replace its body; remove getCurrencyPrecisionMultiplier * [AI] Remove AI-generated release notes workflow and support custom filenames (#7963) * [AI] Relax release-notes filename convention Allow descriptive filenames (e.g. add-payee-autocomplete.md) for upcoming release notes instead of requiring {PR_NUMBER}.md. The PR number was only used to build the [#1234](.../pull/1234) link in the generated changelog. The generation script now resolves the PR per file by finding the commit that added it (git log --diff-filter=A --follow) and querying GitHub's commits/{sha}/pulls endpoint. Numeric filenames remain valid via a fast path. Also retires the CodeRabbit/OpenAI-triggered auto-creator workflow, which existed to guess summaries and stamp the PR-numbered filename; neither is needed once contributors can pick a slug up front. * Add release notes for PR #7963 * [AI] Use execFile to look up release-note add-commits resolvePrNumber() interpolated a path from fs.readdir into a shell- evaluated `git log` command. Switch to execFile with an argv array so filenames containing shell metacharacters can't break out of the intended command. * [AI] Drop duplicate release note added by the to-be-removed auto-creator The CodeRabbit-triggered workflow ran one last time from master before this PR removes it, and committed upcoming-release-notes/7963.md duplicating the existing relax-release-notes-filenames.md entry. Keep the slug-named note since it exercises the new flexible-filename code introduced in this PR. * [AI] Don't fail release-notes generation on transient API errors fetchPrForCommit() handled non-OK HTTP responses but let fetch() and res.json() exceptions propagate, so a single network blip or malformed response would abort the whole release-notes generation. Wrap them in a try/catch that logs and returns null, matching the pattern already used in resolvePrNumber for execFile errors. * [AI] Address CodeRabbit full-review nits - bin/release-note-generator.ts: tighten slug regex to reject trailing and consecutive dashes (matching slugify output), and make slugify fall back to "untitled" so an all-non-alphanumeric input can't produce a hidden ".md" filename. - packages/ci-actions/bin/release-notes-check.mjs: switch to execFile for git fetch/diff, matching release-notes-generate.mjs and removing shell interpolation of BASE_REF. - packages/ci-actions/bin/release-notes-generate.mjs: explicitly check GITHUB_REPOSITORY before splitting, consistent with the other env var guards a few lines below. - upcoming-release-notes/relax-release-notes-filenames.md: fix author casing (matiss -> MatissJanis) so changelog attribution is correct. * [AI] Reject empty release-note bodies content.trim().split('\n').length === 1 is true for the empty string (''.split('\n') returns [''] of length 1), so blank notes slipped past the single-line check. Reject empty trimmed content explicitly. * [AI] Resolve PR numbers from commit subjects instead of GitHub's API parseReleaseNotes was doing one GitHub API round-trip per non-numeric release-note file. That scales badly for release generation, and the docs site's generate-upcoming-release-notes.mjs runs on every docs build — so contributors were hitting the GitHub API (or failing 401 without a token) every time they previewed docs locally. actualbudget squash-merges every PR through the GitHub UI, which appends "(#NNNN)" to the resulting commit subject. So: git log -1 --format=%s -- <path> plus a /\(#(\d+)\)\s*$/ match recovers the PR number without touching the network, and works offline / without a GITHUB_TOKEN. Side effect: switched from "first commit that added this file" to "most recent commit touching this file", which is what we actually want — when a file is renamed (e.g. 7907.md -> 7954.md when a wrong PR number is corrected), the changelog should point at the rename PR, not the original add. The SHA->PR cache and fetchPrForCommit go away; no longer needed. If a file's subject doesn't match (direct push to master, manually rewritten subject), the entry still emits without a PR-link prefix — same graceful degradation as before. * [AI] Pin PR-number lookup to each note's add commit resolvePrNumber was using git log -1 with no diff filter, returning the latest commit that touched the file. That's fine until someone edits an existing release note in a follow-up PR (typo fix, author correction) — at which point the changelog entry would suddenly point at the wrong PR. Add --diff-filter=A so the lookup pins to the commit that originally added the path. Empirically verified against this repo: renames keep working (git records a rename as A at the new path when --follow isn't used), and the edit case now correctly returns the original add commit instead of the most recent touch. --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Add GitHub workflow to block PRs with "do not merge" label (#8090) * [AI] Add CI job that fails when 'do not merge' label is set * [AI] Rename do not merge check job to "Block PRs with do not merge label" * [AI] Rename do not merge workflow to "Block PRs with do not merge label" * [AI] Add release notes for do not merge CI check * Update 8090.md --------- Co-authored-by: Claude <[email protected]> * [AI] Persist bank sync status in the accounts table (#8017) * [AI] Persist bank sync status in the accounts table Extracts the persisted bank-sync-status half of #7782 (by @jcam): adds a bank_sync_status column to the accounts table, writes the status (pending/ok/failed/reauth-required/attention-required) during native bank syncs, and reads the persisted value in the UI (sidebar, account header, mobile account pages, and the sync banner) instead of ephemeral Redux state. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Add release note for persisted bank sync status https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Persist only durable failure states, keep pending ephemeral Addresses review feedback: a transient 'pending' write could get stuck in the DB (and propagated via CRDT) if the app closed mid-sync. The DB now only stores durable result states (ok / failed / reauth-required / attention- required); pending stays in ephemeral Redux state (account.accountsSyncing) as before. The UI reads only the persisted failure state via isAccountFailedSync, and the BankSyncStatus banner reverts to the ephemeral in-flight count. Also extracts a persistBankSyncError helper and inlines a redundant wrapper. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Un-export AccountSyncSidebar, refine release note - AccountSyncSidebar is internal again; drop the export-only-for-test and its test (the failure logic is already covered by syncStatus.test.ts). - Credit MatissJanis in the release note and make it user-centric. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Publish account changes in bank-sync sync-events handleSyncResponse writes accounts.last_sync and accounts.bank_sync_status, but the sync-events following it only declared tables: ['transactions'], so clients only refetch useAccounts when the event includes 'accounts'. Add 'accounts' to the six emissions that follow handleSyncResponse (the four link flows and the two batch-sync finals) so the persisted account changes are published everywhere, not just on the triggering client. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Re-timestamp bank_sync_status migration after master A newer migration (add_tags_hidden) landed on master, so bump the bank_sync_status migration's timestamp to remain the latest and satisfy the migration-ordering check. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD --------- Co-authored-by: Claude <[email protected]> * Remove environment from release notes workflow (#8091) * Remove environment from release notes workflow Removed the environment specification from the release notes workflow. * Update release-notes CI job configuration Removed the unnecessary 'environment' from the release-notes CI job. * [AI] Enable "do not merge" check on merge queue events (#8092) * [AI] Run do-not-merge check on merge_group events The block-do-not-merge workflow only triggered on pull_request events, so it never ran in the merge queue and could not be made a required check. Adding the merge_group trigger lets the job run and pass in the queue context (where pull_request labels are absent), allowing it to be required. * [AI] Add release notes for merge queue do-not-merge fix --------- Co-authored-by: Claude <[email protected]> * Make payee & categories searching to be case-insentive (#8079) * make payee & categories searching to be case-insentive * add release notes * [autofix.ci] apply automated fixes * Update VRT screenshots Auto-generated by VRT workflow PR: #8079 * update release-note * [autofix.ci] apply automated fixes * fix release-note format --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Add files via upload (#8096) * [AI] Fix incorrect schedule value when saving full amount (#8085) If one has a yearly schedule and the budget template uses "Cover each occurence when it occurs", it still showed a value for the yearly schedule even though it's not the month where the schedule occurs. Co-authored-by: Gemini <[email protected]> * feat: add SharedArrayBuffer warning indicator in title bar (#7922) * feat: add SharedArrayBuffer warning ind…
shawalli
added a commit
to shawalli/actual
that referenced
this pull request
Jul 13, 2026
* bring release branch up to date (#8333) * :wrench: Prevent release branch workflow from running on forks (#7949) * prevent release branch worfklow from running on forks * release notes * automation UI: add per-category notes and tooltip (#7906) * add per-automation note * add tooltip to automation button * note * tweak placeholder * popover placement * tooltip styling * [AI] Fix split double-counting in balance forecast (#7955) * [AI] Fix split double-counting in balance forecast * [AI] Add release note for forecast split fix * [AI] Move UserDirectoryPage to admin directory (#7951) * [AI] Fix ineffective dynamic import of responsive/wide UserDirectoryPage was statically imported from ./responsive/wide in FinancesApp.tsx, which prevented the bundler from splitting the wide chunk into its own bundle (since responsive/index.tsx dynamically imports it). Import UserDirectoryPage directly from its source so the dynamic import in responsive/index.tsx can move the module into the expected chunk. * [AI] Add release note for #7951 --------- Co-authored-by: Claude <[email protected]> * only count PRs based on master towards maintainer points (#7958) * only count PRs to master * note * [AI] Add blog post announcing no-advertising Discord rule (#7914) * [AI] Add blog post announcing no-advertising Discord rule https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 * [AI] Rewrite no-advertising Discord blog post in maintainer voice https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 * [AI] Quote blog front matter description to fix YAML parse error https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 * [AI] Hyphenate "privacy-oriented" compound adjective in blog post https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 * [AI] Reword advertising policy scope per review feedback https://claude.ai/code/session_01VPN1uPikyDXd1A5mSFppr4 --------- Co-authored-by: Claude <[email protected]> * Add stacked net worth docs (#7948) Add some information regarding how to use the stacked net worth report. * move crossover report docs out of experimental (#7953) * move crossover report docs out of experimental * coderabbit * Trim schedule names on save (#7959) * [AI] Trim schedule names on save * [AI] Rename release note for PR number * [AI] Fix last zizmor issues (#7975) * [AI] Address zizmor findings on workflows Replace actions-ecosystem/action-add-labels and action-remove-labels with `gh` CLI calls (superfluous-actions). Silence the six dangerous-triggers findings on pull_request_target/workflow_run workflows with inline `# zizmor: ignore[dangerous-triggers]` and a short rationale — each workflow already follows GitHub's documented safe pattern (no PR code checkout, or validated artifacts only). * [AI] Add release note for zizmor workflow fixes --------- Co-authored-by: Claude <[email protected]> * [AI] Add Claude Code skills for docs, commits, and PR review (#7967) * [AI] Add Claude Code skills for docs, commits, and PR review Add three project-scoped skills under .claude/skills/ so any contributor using Claude Code in this repo gets the same conventions applied automatically: writing-actual-docs (points Claude at writing-docs.md before any docs work), committing-actual-changes (points Claude at pr-and-commit-rules.md before any commit/PR so the [AI] prefix and template-blank rule are followed), and review-actual-pr (end-to-end offline PR review with browser testing via playwright-cli, never posts to GitHub). All skill paths and tool assumptions are repo-relative (resolved via git rev-parse --show-toplevel) so they work on any contributor's machine, not just the author's. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Fix remaining hardcoded $HOME path in PR-review playbook The Step 3 highlight-overlay example still referenced $HOME/.claude/skills/review-actual-pr/... which only resolves on the original author's machine. Switch to the same git rev-parse --show-toplevel pattern used elsewhere in the skill so it works for any contributor with a checkout of the repo. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Add release note for #7967 Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Drop "add AI generated label" instruction now that it auto-applies The "AI generated" PR label is now applied automatically by GitHub Actions to any PR whose title starts with [AI], so the manual "add this label" instruction is stale. It was also misleading for outside contributors, who cannot apply labels on PRs against this repo regardless. Updated the canonical rules file, the committing-actual-changes skill, and the review-actual-pr code-review rubric to describe the prefix as the single trigger and note that the label follows automatically. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * Update Claude Code skills description Simplified the description of Claude Code skills. * [AI] Allow cat and mv in PR-review skill's tool allowlist The workflow saves the final report via `cat > review.md <<'EOF'` (step 6) and rotates a stale prior report via `mv` (step 2, re-runs), but the allowed-tools line did not permit either, so those commands would prompt or fail at runtime. Add Bash(cat:*) and Bash(mv:*) — keeping the allowlist tight rather than broadening to Bash(*), so unrelated shell commands still require explicit authorization. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> --------- Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> * [Docs] UI Budget automations & month-end cleanup (#7863) * Add files via upload * Create documentation for budget automation feature Added documentation for the budget automation feature, detailing its functionalities, usage, and examples. * Add files via upload * Revise budget automation documentation for clarity Updated the documentation for budget automation, enhancing clarity and consistency in the descriptions of features and options. * [autofix.ci] apply automated fixes * Update Markdown headers for budget automation section * Add files via upload * Improve formatting in budget automation documentation Updated formatting and added line breaks for better readability in the budget automation documentation. * [autofix.ci] apply automated fixes * Fix HTML line breaks in budget-automation.md Updated HTML line breaks from '</br>' to '<br>' in budget automation documentation. * Fix HTML line breaks in budget automation documentation * Fix headings and formatting in budget-automation.md Updated formatting and corrected headings in budget automation documentation. * Add budget-automation to sidebar items * Add files via upload * Add files via upload * Revise budget automation documentation Updated budget automation documentation to clarify usage of notes templates and detailed instructions for month-end cleanup processes, including named pools and weight calculations. * [autofix.ci] apply automated fixes * Refactor budget automation documentation for clarity Updated various sections for clarity and consistency, including grammar corrections and improved phrasing. * [autofix.ci] apply automated fixes * Enhance budget automation documentation Updated budget automation documentation with new blog links and improved formatting. * Fix links in budget-automation.md Updated links in the budget automation documentation to remove 'docs' prefix for consistency. * Revise budget automation documentation with updates Updated images and text for budget automation documentation, including corrections and enhancements to clarity. * Improve clarity and add save reminders in budget automation Updated wording for clarity and added reminders for saving work. * Update budget automation documentation for clarity Clarify the process of handling leftover funds in the budget automation script. * [autofix.ci] apply automated fixes * Add 'overfund' and 'overfunded' to spelling expect list * Update spelling expectations by removing 'overfunded' Removed 'overfunded' from the spelling expectations. * Add files via upload * 'overfund' to 'overfunded' First the bot tells me overfunded isn't needed if overfund is there. Now, it tells me that overfunded IS needed. I give up. * Enhance budget automation documentation Added new sections on automation adjustments, moved some sections around, added horizontal separators. * Update images and descriptions in budget automation docs * Add files via upload * Add automation notes section to budget automation docs Added a section on automation notes to document how automations, balance caps, and long-term goals can have associated notes for clarity and tracking. * Add files via upload * Update budget automation examples in documentation * Add files via upload * Apply suggestions from code review Co-authored-by: Matt Fiddaman <[email protected]> * [autofix.ci] apply automated fixes * Add 'unmigrate' to spelling expectations * Improve clarity in budget automation documentation Clarified descriptions for budget automation features and improved wording for better understanding. * Correct spelling of 'unmigrate' to 'Unmigrate' They are the same and github is punking me again. * Clarify automation notes description * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Fix typos in budget-automation documentation Corrected typos and improved clarity in the budget automation documentation. --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> * Bump the npm_and_yarn group across 1 directory with 3 updates (#7980) Bumps the npm_and_yarn group with 3 updates in the / directory: [ip-address](https://github.com/beaugunderson/ip-address), [tmp](https://github.com/raszi/node-tmp) and [webpack](https://github.com/webpack/webpack). Updates `ip-address` from 10.0.1 to 10.1.0 - [Commits](https://github.com/beaugunderson/ip-address/compare/v10.0.1...v10.1.0) Updates `tmp` from 0.2.5 to 0.2.7 - [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md) - [Commits](https://github.com/raszi/node-tmp/compare/v0.2.5...v0.2.7) Updates `webpack` from 5.102.1 to 5.107.2 - [Release notes](https://github.com/webpack/webpack/releases) - [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md) - [Commits](https://github.com/webpack/webpack/compare/v5.102.1...v5.107.2) --- updated-dependencies: - dependency-name: ip-address dependency-version: 10.1.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: tmp dependency-version: 0.2.7 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: webpack dependency-version: 5.107.2 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * [AI] Upgrade dependencies to resolve security advisories (#7982) * [AI] Upgrade dependencies to resolve security advisories Resolve 9 Dependabot security alerts via version upgrades: - rollup: remove the resolutions pin that forced workbox-build's rollup ^2.79.2 up to vulnerable 4.40.1; it now resolves to the patched 2.80.0 (vite 8 uses rolldown, so no rollup 4.x is needed) (CVE-2026-27606) - serialize-javascript: add resolution ^7.0.5 (build-time only; consumers are deep-transitive webpack/terser plugins pinned to ^6) (GHSA-5c6j-r48x-rmvq, CVE-2026-34043) - express-rate-limit ^8.3.2 -> ^8.5.2, pulling ip-address 10.2.0 (CVE-2026-42338) - refresh in-range transitives: bn.js 5.2.3, ajv 8.20.0, glob 10.5.0, path-to-regexp 8.4.2 (CVE-2026-2739, CVE-2025-69873, CVE-2025-64756, CVE-2026-4926, CVE-2026-4923) Not addressed: elliptic (CVE-2025-14505) has no patched release; uuid 8.3.2 (dev-only via sockjs, not reachable) left as-is. https://claude.ai/code/session_018obbND7t9dBZvfvUBBJKFz * [AI] Remove redundant minimatch resolution pins Five of the six minimatch resolutions were no-ops: their consumers use caret ranges (^3.x, ^5.x, ^9.x, ^10.x) that already float to versions patched against CVE-2026-26996 (3.1.5, 5.1.9, 9.0.9, 10.2.5). Only serve-handler pins minimatch to exactly 3.1.2 (vulnerable), so the single targeted "[email protected]" override is kept. The resolved lockfile is unchanged. https://claude.ai/code/session_018obbND7t9dBZvfvUBBJKFz * Add release notes for PR #7982 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Fix fatal error when launching PWA while offline (#7978) * [AI] Fix fatal error when launching PWA while offline (#7886) The Vite migration in 26.5 changed how `data-file-index.txt` is generated. The previous shell-based `cp ... migrations/*` and `find * -type f` skipped dotfiles by default, but the new `fs.cp`/`fs.readdir` recursive calls include them. As a result the legacy `.force-copy-windows` marker file ended up in the index and the app fetched it on every startup. The workbox precache globs only match files with known extensions, so this dotfile is never cached; opening the PWA offline therefore failed the entire `populateDefaultFilesystem` step and rendered a fatal error. Skip dotfiles when generating the index (restoring the pre-26.5 behavior) and remove the stale marker file. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * Add release notes for PR #7978 * Delete upcoming-release-notes/7886.md --------- Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Revert "[AI] chore: update alpine base image to 3.23.4" (#7985) * Revert "[AI] chore: update alpine base image to 3.23.4 (#7939)" This reverts commit 366045a6b071e431f4afe7aef6a7fd1a0af15245. * Add release notes for PR #7985 * Delete upcoming-release-notes/7985.md --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Fix small visual issues on mobile transaction entry (#7962) * [AI] Fix small visual issues on mobile transaction entry - Left-align text in the date field (was centered on mobile browsers). - Show focus border on the whole icon-prefixed field (date, notes) instead of only under the input, and drop the rounded corners that leaked through from the inner Input's box-shadow. - Balance focused vs unfocused borders on the amount field so the page no longer shifts down by 1px when it gains focus. * [AI] Left-align mobile date field via WebKit pseudo-element iOS/WebKit renders <input type="date"> text inside the ::-webkit-date-and-time-value pseudo-element, which ignores the input's own text-align. Target the pseudo-element directly. * Add release notes for PR #7962 * [AI] Prevent icon shift when disabling mobile transaction fields When the disabled state of a mobile transaction field changed, the icon could drift up by 1px. Two contributing factors: - The wrapper's emotion class was regenerated when disabled toggled (because backgroundColor was baked into it). Moving the background to an inline style keeps the wrapper's className constant. - The icon was a flex item with intrinsic height being centered by the wrapper in an even-pixel content area, which is a half-pixel centering that can round inconsistently across re-layouts. Stretch the icon container to the full wrapper height and center the SVG internally so the icon's final position no longer depends on the wrapper recalculating cross-axis offsets. * Update VRT screenshots Auto-generated by VRT workflow PR: #7962 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Restrict owner-only sync-server file management endpoints (#7977) * [AI] Restrict owner-only sync-server file management endpoints The /delete-user-file, /reset-user-file, and /user-create-key endpoints guarded access via requireFileAccess, which accepted any user holding a user_access row. A shared collaborator could therefore mark another owner's hosted budget file as deleted, reset its sync state, or rewrite its encryption key. Add a stricter requireFileOwner helper (owner or server admin only) and apply it to the three management endpoints. requireFileAccess keeps its shared-access fallback for the collaboration endpoints (sync, upload, download, get/update filename, get/create encryption key consumers). Fixes GHSA-23vm-ffgg-qvjr. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Align release-note filename with PR number Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * Update release notes for sync-server endpoint restrictions Clarified the restriction on sync-server endpoints to only allow file owners and admins to perform owner-only file-management actions. * Update upcoming-release-notes/7977.md Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * :iphone: Fallback to direct worker on ios (#7971) * fallback to old worker on ios * release note * Correct spelling of 'iOS' in release notes * Improve Tag Filter UX (#7848) * [AI] Make TypeScript work in test files across packages Match the CRDT package's tsconfig pattern in loot-core, desktop-client, api, and desktop-electron so test files participate in the project graph (IDE intellisense, project-wide typecheck) while production builds still emit clean declaration files. - Remove test-file exclusions from each package's main tsconfig - Add tsconfig.build.json for loot-core and api with test exclusions, used by the build scripts - Add e2e/tsconfig.json for desktop-client and desktop-electron with Playwright types - Fix latent type errors in test files now caught by typecheck - Disable typescript/unbound-method for test files (mock matcher pattern) Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Address review feedback on test type fixes - goal-template.test.ts: extract amounts to typed locals so single-value assertions no longer compare against unknown - category-template-context.test.ts: replace `as unknown as DbCategory` double-cast with a fully-typed object using `satisfies DbCategory` (the previous mock had `is_income: true` which doesn't match the `1 | 0` shape the cast was hiding) - api/tsconfig.build.json: broaden test exclude pattern to `**/*.test.ts` Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Drop tsconfig.build.json for loot-core and api The build-config indirection was incomplete protection: typecheck (`tsgo -b` against the main tsconfig, which now includes test files) already emits `*.test.d.ts` into `@types/`, and the build step does not clean before re-emitting. The same is observable in crdt's `dist/`, which currently contains test declarations on disk. What actually keeps test declarations out of the npm tarball is the `files` field in package.json — and loot-core already uses that mechanism for source files (`\!src/**/*.test.ts`). Extending the same pattern to `@types/` is more direct than maintaining a duplicate tsconfig that doesn't reliably do its job. - Delete loot-core/tsconfig.build.json; revert build to `tsgo -b`; add `\!@types/**/*.test.d.ts*`, `\!@types/**/__tests__/**`, `\!@types/**/__mocks__/**` to `files`. - Delete api/tsconfig.build.json; revert build to `vite build && tsgo --emitDeclarationOnly`; add `\!@types/**/*.test.d.ts*` to `files`. Verified: `yarn pack --dry-run` excludes all test declarations from both packages while production declarations still pack (428 .d.ts files for loot-core, methods.d.ts for api). Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * first pass at implementation * finished implementing what I feel would be a good user experience * padding update * added ability to use tab to select * release notes * updated release notes * auto highlights first entry * removed debug info * linting formatting * updated behavior with tags in the middle of stuff * minor improvements to ux * extracted TagAutocomplete functionality into its own file * rewrote TagAutocomplete using react-aria-components from scratch * linting * restored old autocomplete since I'm no longer using it * linting * capped results at 10 * bugfix * used tag css hook instead of notes tag formatter * added mobile support * fixed bug where inserting a tag at the end of the note wouldn't fire onChange handler * fixed bug where note would hover even though field was not focused * fixed bug with currentWord detection * some more minor UI bugs with the mobile UI * removed log statement * added aria-label * [autofix.ci] apply automated fixes * name to Input * updatedt ests * fixed tests * whitespace adjustment * removed debug from test * added tests and made a few fixes * tried to fix vrt * some new hooks to use * removed log statement * removed input from useCursorPosition * input ref value hook now triggers on mount * add extra padding * hide browser autocomplete when our popup is shown to avoid doubles * useFilteredTags hook and adjustments to mobile tag UI * switched from opacity to height transitioning * sorted filtered tags by startsWith first * updated highlighting logic for mouseover * [autofix.ci] apply automated fixes * fix tag ordering * button type * [autofix.ci] apply automated fixes * release note update * release note to trigger ci * reverted db change * Revert "reverted db change" This reverts commit 24ce5450e5e4261e77fe5056620c240da22869a3. * can now filter by tags without hashes * extracted a method and added a new hasAnyTags rule * added hasAnyTag, still need to figure out why tests are failing * fixed unit tests * release notes * fixed based on coderabbit * tag.toLowerCase() * variable scope fix * fixed some focus-related bugs * allow creating tags in the dropdown for desktop * fixed focus issues with useCursorPosition * added Create Tag functionality to mobile * tests and added some length clipping as qol * can now use enter to submit new tag properly * centralized overflow CSS for tags * centered the text horizontally * added textnowrap * release notes * linting * fixed issue with async keydown handler * specified only to use new tag css for the autocomplete stuff * forgot to add new option to tag table * removed Trans * started working on multiselect * multiselect is now functional * finished multiAutocomplete implementation * [autofix.ci] apply automated fixes * removed double input * added multi autocomplete to rule editor * adjusted padding for TagMultiAutocomplete * adjusted hover cursor * release notes * fixed rule conditions * added tag styling to filter multiselect * spacing adjustment * release notes for retriggering build --------- Co-authored-by: github-actions[bot] <[email protected]> Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: Alec Bakholdin <alecbakholdin.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * Add Iranian Rial (#7945) * Add Iranian Rial * Rename file so Ci passes * [AI] Use fixed version for Playwright tests (#7965) * [AI] Pin Electron Playwright version to 99.9.9 The version number at the bottom of the Management page is sourced from package.json via app.getVersion(), so each release rotates the dynamic version string in VRT screenshots. The browser bundle already swaps in a static '99.9.9' for Playwright (browser-preload.js); mirror that in the Electron bootstrap data so desktop VRT snapshots don't break on version bumps. Existing snapshots need to be regenerated once (via /update-vrt on the PR) since they were captured with the live package.json version. * Update VRT screenshots Auto-generated by VRT workflow PR: #7965 * [AI] Pin Playwright server version to 99.9.9 The Management page footer also renders the sync server version, which 'get-server-version' fetches from the sync-server's /info endpoint (its own package.json). Short-circuit getServerVersion() to '99.9.9' when running under Playwright so VRT snapshots stay stable across releases. * Update VRT screenshots Auto-generated by VRT workflow PR: #7965 * [AI] Set 'playwright' userAgent on Electron BrowserWindow under Playwright playwright.config.ts only sets userAgent for direct chromium launches — _electron.launch() leaves the BrowserWindow with Chromium's default UA, so Platform.isPlaywright (which checks navigator.userAgent) is false in the renderer. That's why the ServerContext shortcut wasn't pinning the server version for desktop VRT snapshots. Force the UA on the webContents when EXECUTION_CONTEXT=playwright so renderer-side Playwright checks light up. * Update VRT screenshots Auto-generated by VRT workflow PR: #7965 * [AI] Preserve Electron substring in Playwright userAgent Replacing the Electron renderer's UA with bare 'playwright' broke environment.isElectron() (it greps for 'Electron' in navigator.userAgent), which rerouted ConfigServer.tsx into the external-server branch — the sync-server e2e test could no longer find the Start button to navigate to the bootstrap page, so its snapshot kept falling through every /update-vrt unchanged. Append ' playwright' to the existing Electron UA instead, and widen the Platform.isPlaywright check to a substring match so both 'playwright' (chromium tests) and 'Electron/… playwright' (electron tests) resolve to true. * Update VRT screenshots Auto-generated by VRT workflow PR: #7965 * Add release notes for PR #7965 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] New chip on payee field now surfaces a lack of geolocation permissions (#7883) * New chip on payee field now surfaces a lack of geolocation permissions * Addressing coderabbit feedback * Update category in release notes for transaction editing Changed category from Maintenance to Enhancements for clarity. --------- Co-authored-by: Matiss Janis Aboltins <[email protected]> * fix schedule modal scrollbars (#7992) * [AI] Custom highlight for added sync items: transaction table and sidebar (#7998) * Add new CSS variables for text items in dark theme * Add new CSS variables for table and sidebar items * Add new CSS variables for table and sidebar items * Update sidebar account style for updated state * Enhance valueStyle with color for added items * [autofix.ci] apply automated fixes * Add new theme variables for table and sidebar * Add color variables to added sync items Add color variables for enhanced visibility of items. * [AI] Apply added-row styling to transaction notes cell Co-authored-by: Cursor <[email protected]> --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Cursor <[email protected]> * Add Pakistani PKR currency (#7993) Co-authored-by: Awais Saeed <[email protected]> * add trend line to line graphs (#7954) * add trend line to line graphs * note * add to options * split trend generation logic into seperate handler, add test * tighten types * Goal Templates keyboard shortcut (#7912) * add shortcut * note * change shortcut to ctrl-t * shift t * [AI] Add npm minimal age gate for supply-chain defense (#8011) * [AI] Add npmMinimalAgeGate to block dependency versions newer than 3 days * [autofix.ci] apply automated fixes * [AI] Add release notes for npm minimal age gate --------- Co-authored-by: Claude <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * Add initial docs for Enable Banking (#7961) * Add initial docs for Enable Banking * Delete upcoming-release-notes/7961.md * [AI] Fix docusaurus docs build (#8018) * [AI] Fix docs build by pinning webpackbar to v7 webpack 5.106+ removed deprecated ProgressPlugin options, which breaks the older webpackbar 6.0.1 that Docusaurus 3.10.0 depends on. The build fails with "Progress Plugin has been initialized using an options object that does not match the API schema" (unknown properties name/color/ reporters/reporter). Add a webpackbar ^7.0.0 resolution, matching the upstream fix in Docusaurus 3.10.1 (facebook/docusaurus#11981). * Add release notes for PR #8018 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * add EB docs to sidebar (#8019) * 🔖 (26.6.0) (#7947) * 🔖 (26.6.0) * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * Update check-spelling metadata * Generate release notes for v26.6.0 * add release summary * links * Generate release notes for v26.6.0 * update links * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * add EB link * Add initial docs for Enable Banking (#7961) * Add initial docs for Enable Banking * Delete upcoming-release-notes/7961.md * [Docs] UI Budget automations & month-end cleanup (#7863) * Add files via upload * Create documentation for budget automation feature Added documentation for the budget automation feature, detailing its functionalities, usage, and examples. * Add files via upload * Revise budget automation documentation for clarity Updated the documentation for budget automation, enhancing clarity and consistency in the descriptions of features and options. * [autofix.ci] apply automated fixes * Update Markdown headers for budget automation section * Add files via upload * Improve formatting in budget automation documentation Updated formatting and added line breaks for better readability in the budget automation documentation. * [autofix.ci] apply automated fixes * Fix HTML line breaks in budget-automation.md Updated HTML line breaks from '</br>' to '<br>' in budget automation documentation. * Fix HTML line breaks in budget automation documentation * Fix headings and formatting in budget-automation.md Updated formatting and corrected headings in budget automation documentation. * Add budget-automation to sidebar items * Add files via upload * Add files via upload * Revise budget automation documentation Updated budget automation documentation to clarify usage of notes templates and detailed instructions for month-end cleanup processes, including named pools and weight calculations. * [autofix.ci] apply automated fixes * Refactor budget automation documentation for clarity Updated various sections for clarity and consistency, including grammar corrections and improved phrasing. * [autofix.ci] apply automated fixes * Enhance budget automation documentation Updated budget automation documentation with new blog links and improved formatting. * Fix links in budget-automation.md Updated links in the budget automation documentation to remove 'docs' prefix for consistency. * Revise budget automation documentation with updates Updated images and text for budget automation documentation, including corrections and enhancements to clarity. * Improve clarity and add save reminders in budget automation Updated wording for clarity and added reminders for saving work. * Update budget automation documentation for clarity Clarify the process of handling leftover funds in the budget automation script. * [autofix.ci] apply automated fixes * Add 'overfund' and 'overfunded' to spelling expect list * Update spelling expectations by removing 'overfunded' Removed 'overfunded' from the spelling expectations. * Add files via upload * 'overfund' to 'overfunded' First the bot tells me overfunded isn't needed if overfund is there. Now, it tells me that overfunded IS needed. I give up. * Enhance budget automation documentation Added new sections on automation adjustments, moved some sections around, added horizontal separators. * Update images and descriptions in budget automation docs * Add files via upload * Add automation notes section to budget automation docs Added a section on automation notes to document how automations, balance caps, and long-term goals can have associated notes for clarity and tracking. * Add files via upload * Update budget automation examples in documentation * Add files via upload * Apply suggestions from code review Co-authored-by: Matt Fiddaman <[email protected]> * [autofix.ci] apply automated fixes * Add 'unmigrate' to spelling expectations * Improve clarity in budget automation documentation Clarified descriptions for budget automation features and improved wording for better understanding. * Correct spelling of 'unmigrate' to 'Unmigrate' They are the same and github is punking me again. * Clarify automation notes description * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Fix typos in budget-automation documentation Corrected typos and improved clarity in the budget automation documentation. --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: github-merge-queue <[email protected]> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> Co-authored-by: Mats Nilsson <[email protected]> Co-authored-by: Juulz <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Improve Balance Forecast captions (#7957) * [AI] Add visible low point helper for forecasts * [AI] Show ending balance in forecast report * [AI] Show ending balance on forecast card * [AI] Update balance forecast report snapshots * [AI] Add release note for forecast captions * [AI] API: improve messaging for version/schema mismatch errors (#8026) * [AI] Improve messaging for API version/schema mismatch errors When an outdated client or @actual-app/api connects to a budget whose data uses a newer database schema, sync-apply fails with a cryptic "no such column" error that surfaced as a generic download/sync error. Add a version-mismatch message in getDownloadError/getSyncError, gated on the actual SQLite schema-error signature (no such column/table) so other invalid-schema failures keep their generic messaging and otherwise compatible API versions remain usable. * [AI] Set release note author to MatissJanis * Add release notes for PR #8026 * [AI] Address review: use Vitest globals and remove duplicate release note - Drop the explicit `vitest` import in errors.test.ts and rely on the configured test globals (per CodeRabbit review). - Remove the duplicate 8021.md release note, keeping the PR-numbered 8026.md with the clearer description. * [AI] Avoid i18n in loot-core for schema-mismatch message Return the schema-mismatch error as a plain string instead of going through i18next, and drop the i18next setup from the test. loot-core does not depend on i18n, and this message is surfaced verbatim through the programmatic API. * [AI] Remove unnecessary code comments * [AI] Add missing-meta test for getDownloadError --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Fix typo in Budget Automation math expression (#8035) * Fix typo in Budget Automation math expression * Remove release note --------- Co-authored-by: youngcw <[email protected]> * [AI] docs: update reset-password instructions (#7950) * [AI] docs: update reset-password instructions Clarify the current host-side command and keep the source-checkout workflow documented. Closes #7943 * [AI] docs: keep npm reset path alongside actual-server * Fix CSV import settings reset when skipping end lines (#7827) * [AI] fix(api): prevent navigator crash when loading @actual-app/api in Node.js (#8037) * [AI] fix(api): prevent navigator crash when loading @actual-app/api in Node.js Problem ------- @actual-app/api 26.5.0 and 26.6.0 throw "ReferenceError: navigator is not defined" on import in Node.js environments. The loot-core shared bundle includes three platform variants: platform.ts – browser (references navigator at module load time) platform.electron.ts – Electron/desktop (uses Node.js os module) platform.api.ts – Node.js API (safe constants only) The API vite build uses `resolve: { conditions: ['api'] }` to pick the right variant via the loot-core package imports map (#shared/platform). However, months.ts was importing via a bare relative path (`./platform`) instead of the imports-map alias (`#shared/platform`). Vite's conditions-based resolution does not apply to relative imports, so the build fell back to platform.ts (the browser variant), bundling navigator references that crash at load time. Fix --- Change months.ts to import `#shared/platform` instead of `./platform`. This goes through the loot-core package imports map, which the vite `api` condition resolves to platform.api.ts — the Node.js-safe variant. platform.api.ts was already added to the repo alongside this condition infrastructure (in the same 26.6.0 release) but the months.ts import was missed, leaving the crash in the published package. Testing ------- Added packages/api/platform.test.ts, which imports @actual-app/core/shared/ platform under the `api` vite condition and asserts that isBrowser, isPlaywright and isIOSAgent are all false. This test: - Fails if platform.api.ts is deleted (module not found) - Fails if platform.api.ts is modified to reference navigator (ReferenceError) - Fails if the api vite condition is removed, falling back to platform.ts which throws ReferenceError at import time in Node.js Verified by Kyle Slattery against a live Actual Budget instance via the actual-flow integration tool (https://github.com/lunchflow/actual-flow). * Add release note * Update upcoming-release-notes/8037.md Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Delete packages/api/platform.test.ts --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * [AI] Move i18n usage outside of loot-core (#8027) * [AI] Move i18n usage outside of loot-core loot-core should be platform-agnostic and free of i18n concerns. This moves all user-facing translated string helpers (rule/schedule labels, error formatters) into desktop-client's #util/{rule,schedule,error} modules, while keeping the underlying logic in loot-core. - Headless @actual-app/api error formatters in loot-core now return plain English strings (the API has no i18n runtime). - The persisted "Unknown" institution name and the platform storage alert use plain strings. - Removed the unused i18next dependency from loot-core. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Address review feedback on i18n-out-of-loot-core PR - Wrap switch default arms in blocks to satisfy noSwitchDeclarations (desktop-client and loot-core getDownloadError) - getSecretsError: return a localized generic message instead of leaking the raw backend error token - getRecurringDescription: always separate the weekend annotation so it no longer renders as "Monday(after weekend)"; add test coverage - IndexedDB quota error: surface a typed 'indexeddb-quota-error' event from loot-core and present the localized alert in desktop-client instead of a hard-coded English string - Persist a null bank name (instead of English "Unknown") when the provider reports no institution, and render a localized fallback in the bank sync UI --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Fix Balance Forecast chart colors with custom themes (#8031) * [AI] Use report theme colors for Balance Forecast chart lines * [AI] Add release notes for Balance Forecast custom theme fix * fix react compiler on Windows (#8049) * hmm.. * note * [Docs] Revise fly.io deployment instructions for nightly builds (#8059) * Revise deployment instructions for nightly builds Updated instructions for deploying unstable versions of Actual. * Clarify fly deploy commands in installation guide Updated deployment commands for clarity and added example for nightly version. * [autofix.ci] apply automated fixes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Scope Electron update to v41 (#8044) * Initial plan * Bump desktop Electron runtime to v42.3.0 * Add release notes entry for PR #8044 * Change author from Copilot to MikesGlitch Updated author information in release notes. * Update node-abi mappings to support Electron 42 ABI detection * Address validation feedback for Electron update PR * Add better-sqlite3 Electron 42 patch * Update lockfile for better-sqlite3 patch * Remove better-sqlite patch protocol and target Electron 41 * Align release note with Electron 41.7.1 change * Update better-sqlite3 ranges to ^12.8.0 --------- Co-authored-by: copilot-swe-agent[bot] <[email protected]> Co-authored-by: Michael Clark <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * [Enhancements] Removed regex from excel formula execution (#7990) * Removed regex from excel formula execution * [autofix.ci] apply automated fixes * Surface error for BUDGET_QUERY * code review --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Fix balance forecast report Y-axis label clipping (#8030) * [AI] Fix balance forecast report Y-axis label clipping * [AI] Add release notes for #8030 * docs: add actual-bench to community projects (#8045) * docs: add actual-bench to community projects * [autofix.ci] apply automated fixes * docs: add release note for actual-bench community entry * [autofix.ci] apply automated fixes * fix: address coderabbit comments * fix: remove upcoming release notes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Add Sort A to Z / Sort Z to A options to budget category groups (#7831) * [AI] Add Sort A to Z / Sort Z to A options to budget category groups (#7831) * Simplify release notes and apply coderabbitai suggestions * [AI] fix(api): trigger SimpleFin batch sync with a single account (#8052) The condition required more than one SimpleFin account before running batch sync, causing a single SimpleFin account to be skipped entirely. Co-authored-by: Claude Opus 4.6 <[email protected]> * add pikapods desktop warning (#8061) * add pikapods desktop warning * better link * add to spelling list * more spelling * [AI] Fix bug when linking accounts (#8006) Fixes a bug that when selecting Link Account from the account page one has to reselect the same account in the modal even though its prepopulated. Co-authored-by: Gemini <[email protected]> * add MXN peso (#8060) * ♻️ remove unnecessary playwright container pulls to speed up CI (#8067) * don't use playwright where it's not needed * note * [AI] Add auto-generated Upcoming Release docs page (#8065) * [AI] Add auto-generated Upcoming Release docs page Adds a docs page that always reflects the current contents of the repo-root upcoming-release-notes/ directory — the changes that have been merged but not yet published in a stable release (i.e. what ships in the nightly/edge builds). - Extract parseReleaseNotes/formatNotes from the release-notes generator into the shared ci-actions util so both the release generator and the docs build reuse the same formatting. - Add a docs build script that regenerates docs/upcoming-release-notes.md on every start/build, with an intro explaining the notes are unreleased and how to try them, plus the categorized notes list. - Wire the generator into the docs start/build scripts, add a sidebar entry next to Release Notes, and gitignore the generated page. https://claude.ai/code/session_01MuY9Phome8uJKH51HbrsQw * [AI] Simplify upcoming-release-notes generator - Declare @actual-app/ci-actions as a workspace dependency and import the shared util by package name instead of a relative cross-package path, so the dependency is registered in the workspace graph. - Resolve the repo root once via new URL() and drop the dirname import. - Use a ternary for the page body instead of let + if/else. https://claude.ai/code/session_01MuY9Phome8uJKH51HbrsQw * Add release notes for PR #8065 * [AI] Remove edge references, keep only nightly in docs Co-authored-by: Matiss Janis Aboltins <[email protected]> * Update packages/docs/scripts/generate-upcoming-release-notes.mjs Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Cursor Agent <[email protected]> Co-authored-by: Matiss Janis Aboltins <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * Bump the npm_and_yarn group across 2 directories with 1 update (#8071) Bumps the npm_and_yarn group with 1 update in the / directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Bumps the npm_and_yarn group with 1 update in the /packages/desktop-client directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Updates `react-router` from 7.13.1 to 7.14.2 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) Updates `react-router` from 7.13.1 to 7.14.2 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) --- updated-dependencies: - dependency-name: react-router dependency-version: 7.14.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: react-router dependency-version: 7.14.2 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * When resetting SimpleFIN credentials, parse error and error_code if response body exists (#8068) * Initial commit * Add release note * Update release note file name to match PR number * Flip operands when checking for 2xx * Release notes grammar * Better release note for non-devs * Simplify to naive solution of checking on nullable response * Hiding tags and tag table bulk actions (#7919) * [AI] Make TypeScript work in test files across packages Match the CRDT package's tsconfig pattern in loot-core, desktop-client, api, and desktop-electron so test files participate in the project graph (IDE intellisense, project-wide typecheck) while production builds still emit clean declaration files. - Remove test-file exclusions from each package's main tsconfig - Add tsconfig.build.json for loot-core and api with test exclusions, used by the build scripts - Add e2e/tsconfig.json for desktop-client and desktop-electron with Playwright types - Fix latent type errors in test files now caught by typecheck - Disable typescript/unbound-method for test files (mock matcher pattern) Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Address review feedback on test type fixes - goal-template.test.ts: extract amounts to typed locals so single-value assertions no longer compare against unknown - category-template-context.test.ts: replace `as unknown as DbCategory` double-cast with a fully-typed object using `satisfies DbCategory` (the previous mock had `is_income: true` which doesn't match the `1 | 0` shape the cast was hiding) - api/tsconfig.build.json: broaden test exclude pattern to `**/*.test.ts` Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Drop tsconfig.build.json for loot-core and api The build-config indirection was incomplete protection: typecheck (`tsgo -b` against the main tsconfig, which now includes test files) already emits `*.test.d.ts` into `@types/`, and the build step does not clean before re-emitting. The same is observable in crdt's `dist/`, which currently contains test declarations on disk. What actually keeps test declarations out of the npm tarball is the `files` field in package.json — and loot-core already uses that mechanism for source files (`\!src/**/*.test.ts`). Extending the same pattern to `@types/` is more direct than maintaining a duplicate tsconfig that doesn't reliably do its job. - Delete loot-core/tsconfig.build.json; revert build to `tsgo -b`; add `\!@types/**/*.test.d.ts*`, `\!@types/**/__tests__/**`, `\!@types/**/__mocks__/**` to `files`. - Delete api/tsconfig.build.json; revert build to `vite build && tsgo --emitDeclarationOnly`; add `\!@types/**/*.test.d.ts*` to `files`. Verified: `yarn pack --dry-run` excludes all test declarations from both packages while production declarations still pack (428 .d.ts files for loot-core, methods.d.ts for api). Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * first pass at implementation * finished implementing what I feel would be a good user experience * padding update * added ability to use tab to select * release notes * updated release notes * auto highlights first entry * removed debug info * linting formatting * updated behavior with tags in the middle of stuff * minor improvements to ux * extracted TagAutocomplete functionality into its own file * rewrote TagAutocomplete using react-aria-components from scratch * linting * restored old autocomplete since I'm no longer using it * linting * capped results at 10 * bugfix * used tag css hook instead of notes tag formatter * added mobile support * fixed bug where inserting a tag at the end of the note wouldn't fire onChange handler * fixed bug where note would hover even though field was not focused * fixed bug with currentWord detection * some more minor UI bugs with the mobile UI * removed log statement * added aria-label * [autofix.ci] apply automated fixes * name to Input * updatedt ests * fixed tests * whitespace adjustment * removed debug from test * added tests and made a few fixes * tried to fix vrt * some new hooks to use * removed log statement * removed input from useCursorPosition * input ref value hook now triggers on mount * add extra padding * hide browser autocomplete when our popup is shown to avoid doubles * useFilteredTags hook and adjustments to mobile tag UI * switched from opacity to height transitioning * sorted filtered tags by startsWith first * updated highlighting logic for mouseover * [autofix.ci] apply automated fixes * fix tag ordering * button type * [autofix.ci] apply automated fixes * release note update * release note to trigger ci * reverted db change * Revert "reverted db change" This reverts commit 24ce5450e5e4261e77fe5056620c240da22869a3. * can now filter by tags without hashes * extracted a method and added a new hasAnyTags rule * added hasAnyTag, still need to figure out why tests are failing * fixed unit tests * release notes * fixed based on coderabbit * tag.toLowerCase() * variable scope fix * fixed some focus-related bugs * allow creating tags in the dropdown for desktop * fixed focus issues with useCursorPosition * added Create Tag functionality to mobile * tests and added some length clipping as qol * can now use enter to submit new tag properly * centralized overflow CSS for tags * centered the text horizontally * added textnowrap * release notes * linting * fixed issue with async keydown handler * specified only to use new tag css for the autocomplete stuff * forgot to add new option to tag table * removed Trans * started working on multiselect * multiselect is now functional * finished multiAutocomplete implementation * [autofix.ci] apply automated fixes * removed double input * added multi autocomplete to rule editor * adjusted padding for TagMultiAutocomplete * adjusted hover cursor * release notes * fixed rule conditions * added tag styling to filter multiselect * spacing adjustment * release notes for retriggering build * added hidden migration * added hidden to models * added tags-hide-all and tags-unhide-all actions * added hide and unhide tags actions * added SelectedTagsButton * added UI elements for hiding/showing tags * release notes * removed delete from ManageTags * added icons to menu * coderabbit * coderabbit * updated mutations for translations * coderabbit * removed not null requirement * attempted to fix tests? * removed duplicate filterTags * [autofix.ci] apply automated fixes * updated release notes * release note update * updated migration timestamp * moved tags menu button --------- Co-authored-by: github-actions[bot] <[email protected]> Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: Alec Bakholdin <alecbakholdin.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * automation UI: improve scaling (#8080) * improve scaling on high zoom levels * note * automation UI: rework balance cap and fix error when clearing fields (#8082) * fix safeNumber error * rework balance cap UI to be more readable * note * add explanation to balance cap * Bump react-router in the npm_and_yarn group across 1 directory (#8072) Bumps the npm_and_yarn group with 1 update in the / directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Updates `react-router` from 7.14.2 to 7.15.0 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) --- updated-dependencies: - dependency-name: react-router dependency-version: 7.15.0 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * [AI] feat(currencies): add currency-precision-aware helpers (#8064) * [AI] feat(currencies): add getDecimalPlaces/getCurrencyPrecisionMultiplier helpers, encodeAmount, currency-aware integerToCurrencyWithDecimal * Fix typo in release note * Use it.each in unit tests * Rename encodeAmount and replace its body; remove getCurrencyPrecisionMultiplier * [AI] Remove AI-generated release notes workflow and support custom filenames (#7963) * [AI] Relax release-notes filename convention Allow descriptive filenames (e.g. add-payee-autocomplete.md) for upcoming release notes instead of requiring {PR_NUMBER}.md. The PR number was only used to build the [#1234](.../pull/1234) link in the generated changelog. The generation script now resolves the PR per file by finding the commit that added it (git log --diff-filter=A --follow) and querying GitHub's commits/{sha}/pulls endpoint. Numeric filenames remain valid via a fast path. Also retires the CodeRabbit/OpenAI-triggered auto-creator workflow, which existed to guess summaries and stamp the PR-numbered filename; neither is needed once contributors can pick a slug up front. * Add release notes for PR #7963 * [AI] Use execFile to look up release-note add-commits resolvePrNumber() interpolated a path from fs.readdir into a shell- evaluated `git log` command. Switch to execFile with an argv array so filenames containing shell metacharacters can't break out of the intended command. * [AI] Drop duplicate release note added by the to-be-removed auto-creator The CodeRabbit-triggered workflow ran one last time from master before this PR removes it, and committed upcoming-release-notes/7963.md duplicating the existing relax-release-notes-filenames.md entry. Keep the slug-named note since it exercises the new flexible-filename code introduced in this PR. * [AI] Don't fail release-notes generation on transient API errors fetchPrForCommit() handled non-OK HTTP responses but let fetch() and res.json() exceptions propagate, so a single network blip or malformed response would abort the whole release-notes generation. Wrap them in a try/catch that logs and returns null, matching the pattern already used in resolvePrNumber for execFile errors. * [AI] Address CodeRabbit full-review nits - bin/release-note-generator.ts: tighten slug regex to reject trailing and consecutive dashes (matching slugify output), and make slugify fall back to "untitled" so an all-non-alphanumeric input can't produce a hidden ".md" filename. - packages/ci-actions/bin/release-notes-check.mjs: switch to execFile for git fetch/diff, matching release-notes-generate.mjs and removing shell interpolation of BASE_REF. - packages/ci-actions/bin/release-notes-generate.mjs: explicitly check GITHUB_REPOSITORY before splitting, consistent with the other env var guards a few lines below. - upcoming-release-notes/relax-release-notes-filenames.md: fix author casing (matiss -> MatissJanis) so changelog attribution is correct. * [AI] Reject empty release-note bodies content.trim().split('\n').length === 1 is true for the empty string (''.split('\n') returns [''] of length 1), so blank notes slipped past the single-line check. Reject empty trimmed content explicitly. * [AI] Resolve PR numbers from commit subjects instead of GitHub's API parseReleaseNotes was doing one GitHub API round-trip per non-numeric release-note file. That scales badly for release generation, and the docs site's generate-upcoming-release-notes.mjs runs on every docs build — so contributors were hitting the GitHub API (or failing 401 without a token) every time they previewed docs locally. actualbudget squash-merges every PR through the GitHub UI, which appends "(#NNNN)" to the resulting commit subject. So: git log -1 --format=%s -- <path> plus a /\(#(\d+)\)\s*$/ match recovers the PR number without touching the network, and works offline / without a GITHUB_TOKEN. Side effect: switched from "first commit that added this file" to "most recent commit touching this file", which is what we actually want — when a file is renamed (e.g. 7907.md -> 7954.md when a wrong PR number is corrected), the changelog should point at the rename PR, not the original add. The SHA->PR cache and fetchPrForCommit go away; no longer needed. If a file's subject doesn't match (direct push to master, manually rewritten subject), the entry still emits without a PR-link prefix — same graceful degradation as before. * [AI] Pin PR-number lookup to each note's add commit resolvePrNumber was using git log -1 with no diff filter, returning the latest commit that touched the file. That's fine until someone edits an existing release note in a follow-up PR (typo fix, author correction) — at which point the changelog entry would suddenly point at the wrong PR. Add --diff-filter=A so the lookup pins to the commit that originally added the path. Empirically verified against this repo: renames keep working (git records a rename as A at the new path when --follow isn't used), and the edit case now correctly returns the original add commit instead of the most recent touch. --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Add GitHub workflow to block PRs with "do not merge" label (#8090) * [AI] Add CI job that fails when 'do not merge' label is set * [AI] Rename do not merge check job to "Block PRs with do not merge label" * [AI] Rename do not merge workflow to "Block PRs with do not merge label" * [AI] Add release notes for do not merge CI check * Update 8090.md --------- Co-authored-by: Claude <[email protected]> * [AI] Persist bank sync status in the accounts table (#8017) * [AI] Persist bank sync status in the accounts table Extracts the persisted bank-sync-status half of #7782 (by @jcam): adds a bank_sync_status column to the accounts table, writes the status (pending/ok/failed/reauth-required/attention-required) during native bank syncs, and reads the persisted value in the UI (sidebar, account header, mobile account pages, and the sync banner) instead of ephemeral Redux state. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Add release note for persisted bank sync status https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Persist only durable failure states, keep pending ephemeral Addresses review feedback: a transient 'pending' write could get stuck in the DB (and propagated via CRDT) if the app closed mid-sync. The DB now only stores durable result states (ok / failed / reauth-required / attention- required); pending stays in ephemeral Redux state (account.accountsSyncing) as before. The UI reads only the persisted failure state via isAccountFailedSync, and the BankSyncStatus banner reverts to the ephemeral in-flight count. Also extracts a persistBankSyncError helper and inlines a redundant wrapper. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Un-export AccountSyncSidebar, refine release note - AccountSyncSidebar is internal again; drop the export-only-for-test and its test (the failure logic is already covered by syncStatus.test.ts). - Credit MatissJanis in the release note and make it user-centric. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Publish account changes in bank-sync sync-events handleSyncResponse writes accounts.last_sync and accounts.bank_sync_status, but the sync-events following it only declared tables: ['transactions'], so clients only refetch useAccounts when the event includes 'accounts'. Add 'accounts' to the six emissions that follow handleSyncResponse (the four link flows and the two batch-sync finals) so the persisted account changes are published everywhere, not just on the triggering client. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Re-timestamp bank_sync_status migration after master A newer migration (add_tags_hidden) landed on master, so bump the bank_sync_status migration's timestamp to remain the latest and satisfy the migration-ordering check. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD --------- Co-authored-by: Claude <[email protected]> * Remove environment from release notes workflow (#8091) * Remove environment from release notes workflow Removed the environment specification from the release notes workflow. * Update release-notes CI job configuration Removed the unnecessary 'environment' from the release-notes CI job. * [AI] Enable "do not merge" check on merge queue events (#8092) * [AI] Run do-not-merge check on merge_group events The block-do-not-merge workflow only triggered on pull_request events, so it never ran in the merge queue and could not be made a required check. Adding the merge_group trigger lets the job run and pass in the queue context (where pull_request labels are absent), allowing it to be required. * [AI] Add release notes for merge queue do-not-merge fix --------- Co-authored-by: Claude <[email protected]> * Make payee & categories searching to be case-insentive (#8079) * make payee & categories searching to be case-insentive * add release notes * [autofix.ci] apply automated fixes * Update VRT screenshots Auto-generated by VRT workflow PR: #8079 * update release-note * [autofix.ci] apply automated fixes * fix release-note format --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Add files via upload (#8096) * [AI] Fix incorrect schedule value when saving full amount (#8085) If one has a yearly schedule and the budget template uses "Cover each occurence when it occurs", it still showed a value for the yearly schedule even though it's not the month where the schedule occurs. Co-authored-by: Gemini <[email protected]> * feat: add SharedArrayBuffer warning indicator in title bar (#7922) * feat: add S…
theonlyrealcolin
pushed a commit
to theonlyrealcolin/actual
that referenced
this pull request
Aug 3, 2026
* fix schedule modal scrollbars (#7992) * [AI] Custom highlight for added sync items: transaction table and sidebar (#7998) * Add new CSS variables for text items in dark theme * Add new CSS variables for table and sidebar items * Add new CSS variables for table and sidebar items * Update sidebar account style for updated state * Enhance valueStyle with color for added items * [autofix.ci] apply automated fixes * Add new theme variables for table and sidebar * Add color variables to added sync items Add color variables for enhanced visibility of items. * [AI] Apply added-row styling to transaction notes cell Co-authored-by: Cursor <[email protected]> --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Cursor <[email protected]> * Add Pakistani PKR currency (#7993) Co-authored-by: Awais Saeed <[email protected]> * add trend line to line graphs (#7954) * add trend line to line graphs * note * add to options * split trend generation logic into seperate handler, add test * tighten types * Goal Templates keyboard shortcut (#7912) * add shortcut * note * change shortcut to ctrl-t * shift t * [AI] Add npm minimal age gate for supply-chain defense (#8011) * [AI] Add npmMinimalAgeGate to block dependency versions newer than 3 days * [autofix.ci] apply automated fixes * [AI] Add release notes for npm minimal age gate --------- Co-authored-by: Claude <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * Add initial docs for Enable Banking (#7961) * Add initial docs for Enable Banking * Delete upcoming-release-notes/7961.md * [AI] Fix docusaurus docs build (#8018) * [AI] Fix docs build by pinning webpackbar to v7 webpack 5.106+ removed deprecated ProgressPlugin options, which breaks the older webpackbar 6.0.1 that Docusaurus 3.10.0 depends on. The build fails with "Progress Plugin has been initialized using an options object that does not match the API schema" (unknown properties name/color/ reporters/reporter). Add a webpackbar ^7.0.0 resolution, matching the upstream fix in Docusaurus 3.10.1 (facebook/docusaurus#11981). * Add release notes for PR #8018 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * add EB docs to sidebar (#8019) * 🔖 (26.6.0) (#7947) * 🔖 (26.6.0) * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * Update check-spelling metadata * Generate release notes for v26.6.0 * add release summary * links * Generate release notes for v26.6.0 * update links * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * add EB link * Add initial docs for Enable Banking (#7961) * Add initial docs for Enable Banking * Delete upcoming-release-notes/7961.md * [Docs] UI Budget automations & month-end cleanup (#7863) * Add files via upload * Create documentation for budget automation feature Added documentation for the budget automation feature, detailing its functionalities, usage, and examples. * Add files via upload * Revise budget automation documentation for clarity Updated the documentation for budget automation, enhancing clarity and consistency in the descriptions of features and options. * [autofix.ci] apply automated fixes * Update Markdown headers for budget automation section * Add files via upload * Improve formatting in budget automation documentation Updated formatting and added line breaks for better readability in the budget automation documentation. * [autofix.ci] apply automated fixes * Fix HTML line breaks in budget-automation.md Updated HTML line breaks from '</br>' to '<br>' in budget automation documentation. * Fix HTML line breaks in budget automation documentation * Fix headings and formatting in budget-automation.md Updated formatting and corrected headings in budget automation documentation. * Add budget-automation to sidebar items * Add files via upload * Add files via upload * Revise budget automation documentation Updated budget automation documentation to clarify usage of notes templates and detailed instructions for month-end cleanup processes, including named pools and weight calculations. * [autofix.ci] apply automated fixes * Refactor budget automation documentation for clarity Updated various sections for clarity and consistency, including grammar corrections and improved phrasing. * [autofix.ci] apply automated fixes * Enhance budget automation documentation Updated budget automation documentation with new blog links and improved formatting. * Fix links in budget-automation.md Updated links in the budget automation documentation to remove 'docs' prefix for consistency. * Revise budget automation documentation with updates Updated images and text for budget automation documentation, including corrections and enhancements to clarity. * Improve clarity and add save reminders in budget automation Updated wording for clarity and added reminders for saving work. * Update budget automation documentation for clarity Clarify the process of handling leftover funds in the budget automation script. * [autofix.ci] apply automated fixes * Add 'overfund' and 'overfunded' to spelling expect list * Update spelling expectations by removing 'overfunded' Removed 'overfunded' from the spelling expectations. * Add files via upload * 'overfund' to 'overfunded' First the bot tells me overfunded isn't needed if overfund is there. Now, it tells me that overfunded IS needed. I give up. * Enhance budget automation documentation Added new sections on automation adjustments, moved some sections around, added horizontal separators. * Update images and descriptions in budget automation docs * Add files via upload * Add automation notes section to budget automation docs Added a section on automation notes to document how automations, balance caps, and long-term goals can have associated notes for clarity and tracking. * Add files via upload * Update budget automation examples in documentation * Add files via upload * Apply suggestions from code review Co-authored-by: Matt Fiddaman <[email protected]> * [autofix.ci] apply automated fixes * Add 'unmigrate' to spelling expectations * Improve clarity in budget automation documentation Clarified descriptions for budget automation features and improved wording for better understanding. * Correct spelling of 'unmigrate' to 'Unmigrate' They are the same and github is punking me again. * Clarify automation notes description * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Fix typos in budget-automation documentation Corrected typos and improved clarity in the budget automation documentation. --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: github-merge-queue <[email protected]> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> Co-authored-by: Mats Nilsson <[email protected]> Co-authored-by: Juulz <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Improve Balance Forecast captions (#7957) * [AI] Add visible low point helper for forecasts * [AI] Show ending balance in forecast report * [AI] Show ending balance on forecast card * [AI] Update balance forecast report snapshots * [AI] Add release note for forecast captions * [AI] API: improve messaging for version/schema mismatch errors (#8026) * [AI] Improve messaging for API version/schema mismatch errors When an outdated client or @actual-app/api connects to a budget whose data uses a newer database schema, sync-apply fails with a cryptic "no such column" error that surfaced as a generic download/sync error. Add a version-mismatch message in getDownloadError/getSyncError, gated on the actual SQLite schema-error signature (no such column/table) so other invalid-schema failures keep their generic messaging and otherwise compatible API versions remain usable. * [AI] Set release note author to MatissJanis * Add release notes for PR #8026 * [AI] Address review: use Vitest globals and remove duplicate release note - Drop the explicit `vitest` import in errors.test.ts and rely on the configured test globals (per CodeRabbit review). - Remove the duplicate 8021.md release note, keeping the PR-numbered 8026.md with the clearer description. * [AI] Avoid i18n in loot-core for schema-mismatch message Return the schema-mismatch error as a plain string instead of going through i18next, and drop the i18next setup from the test. loot-core does not depend on i18n, and this message is surfaced verbatim through the programmatic API. * [AI] Remove unnecessary code comments * [AI] Add missing-meta test for getDownloadError --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Fix typo in Budget Automation math expression (#8035) * Fix typo in Budget Automation math expression * Remove release note --------- Co-authored-by: youngcw <[email protected]> * [AI] docs: update reset-password instructions (#7950) * [AI] docs: update reset-password instructions Clarify the current host-side command and keep the source-checkout workflow documented. Closes #7943 * [AI] docs: keep npm reset path alongside actual-server * Fix CSV import settings reset when skipping end lines (#7827) * [AI] fix(api): prevent navigator crash when loading @actual-app/api in Node.js (#8037) * [AI] fix(api): prevent navigator crash when loading @actual-app/api in Node.js Problem ------- @actual-app/api 26.5.0 and 26.6.0 throw "ReferenceError: navigator is not defined" on import in Node.js environments. The loot-core shared bundle includes three platform variants: platform.ts – browser (references navigator at module load time) platform.electron.ts – Electron/desktop (uses Node.js os module) platform.api.ts – Node.js API (safe constants only) The API vite build uses `resolve: { conditions: ['api'] }` to pick the right variant via the loot-core package imports map (#shared/platform). However, months.ts was importing via a bare relative path (`./platform`) instead of the imports-map alias (`#shared/platform`). Vite's conditions-based resolution does not apply to relative imports, so the build fell back to platform.ts (the browser variant), bundling navigator references that crash at load time. Fix --- Change months.ts to import `#shared/platform` instead of `./platform`. This goes through the loot-core package imports map, which the vite `api` condition resolves to platform.api.ts — the Node.js-safe variant. platform.api.ts was already added to the repo alongside this condition infrastructure (in the same 26.6.0 release) but the months.ts import was missed, leaving the crash in the published package. Testing ------- Added packages/api/platform.test.ts, which imports @actual-app/core/shared/ platform under the `api` vite condition and asserts that isBrowser, isPlaywright and isIOSAgent are all false. This test: - Fails if platform.api.ts is deleted (module not found) - Fails if platform.api.ts is modified to reference navigator (ReferenceError) - Fails if the api vite condition is removed, falling back to platform.ts which throws ReferenceError at import time in Node.js Verified by Kyle Slattery against a live Actual Budget instance via the actual-flow integration tool (https://github.com/lunchflow/actual-flow). * Add release note * Update upcoming-release-notes/8037.md Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Delete packages/api/platform.test.ts --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * [AI] Move i18n usage outside of loot-core (#8027) * [AI] Move i18n usage outside of loot-core loot-core should be platform-agnostic and free of i18n concerns. This moves all user-facing translated string helpers (rule/schedule labels, error formatters) into desktop-client's #util/{rule,schedule,error} modules, while keeping the underlying logic in loot-core. - Headless @actual-app/api error formatters in loot-core now return plain English strings (the API has no i18n runtime). - The persisted "Unknown" institution name and the platform storage alert use plain strings. - Removed the unused i18next dependency from loot-core. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Address review feedback on i18n-out-of-loot-core PR - Wrap switch default arms in blocks to satisfy noSwitchDeclarations (desktop-client and loot-core getDownloadError) - getSecretsError: return a localized generic message instead of leaking the raw backend error token - getRecurringDescription: always separate the weekend annotation so it no longer renders as "Monday(after weekend)"; add test coverage - IndexedDB quota error: surface a typed 'indexeddb-quota-error' event from loot-core and present the localized alert in desktop-client instead of a hard-coded English string - Persist a null bank name (instead of English "Unknown") when the provider reports no institution, and render a localized fallback in the bank sync UI --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Fix Balance Forecast chart colors with custom themes (#8031) * [AI] Use report theme colors for Balance Forecast chart lines * [AI] Add release notes for Balance Forecast custom theme fix * fix react compiler on Windows (#8049) * hmm.. * note * [Docs] Revise fly.io deployment instructions for nightly builds (#8059) * Revise deployment instructions for nightly builds Updated instructions for deploying unstable versions of Actual. * Clarify fly deploy commands in installation guide Updated deployment commands for clarity and added example for nightly version. * [autofix.ci] apply automated fixes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Scope Electron update to v41 (#8044) * Initial plan * Bump desktop Electron runtime to v42.3.0 * Add release notes entry for PR #8044 * Change author from Copilot to MikesGlitch Updated author information in release notes. * Update node-abi mappings to support Electron 42 ABI detection * Address validation feedback for Electron update PR * Add better-sqlite3 Electron 42 patch * Update lockfile for better-sqlite3 patch * Remove better-sqlite patch protocol and target Electron 41 * Align release note with Electron 41.7.1 change * Update better-sqlite3 ranges to ^12.8.0 --------- Co-authored-by: copilot-swe-agent[bot] <[email protected]> Co-authored-by: Michael Clark <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * [Enhancements] Removed regex from excel formula execution (#7990) * Removed regex from excel formula execution * [autofix.ci] apply automated fixes * Surface error for BUDGET_QUERY * code review --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Fix balance forecast report Y-axis label clipping (#8030) * [AI] Fix balance forecast report Y-axis label clipping * [AI] Add release notes for #8030 * docs: add actual-bench to community projects (#8045) * docs: add actual-bench to community projects * [autofix.ci] apply automated fixes * docs: add release note for actual-bench community entry * [autofix.ci] apply automated fixes * fix: address coderabbit comments * fix: remove upcoming release notes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Add Sort A to Z / Sort Z to A options to budget category groups (#7831) * [AI] Add Sort A to Z / Sort Z to A options to budget category groups (#7831) * Simplify release notes and apply coderabbitai suggestions * [AI] fix(api): trigger SimpleFin batch sync with a single account (#8052) The condition required more than one SimpleFin account before running batch sync, causing a single SimpleFin account to be skipped entirely. Co-authored-by: Claude Opus 4.6 <[email protected]> * add pikapods desktop warning (#8061) * add pikapods desktop warning * better link * add to spelling list * more spelling * [AI] Fix bug when linking accounts (#8006) Fixes a bug that when selecting Link Account from the account page one has to reselect the same account in the modal even though its prepopulated. Co-authored-by: Gemini <[email protected]> * add MXN peso (#8060) * ♻️ remove unnecessary playwright container pulls to speed up CI (#8067) * don't use playwright where it's not needed * note * [AI] Add auto-generated Upcoming Release docs page (#8065) * [AI] Add auto-generated Upcoming Release docs page Adds a docs page that always reflects the current contents of the repo-root upcoming-release-notes/ directory — the changes that have been merged but not yet published in a stable release (i.e. what ships in the nightly/edge builds). - Extract parseReleaseNotes/formatNotes from the release-notes generator into the shared ci-actions util so both the release generator and the docs build reuse the same formatting. - Add a docs build script that regenerates docs/upcoming-release-notes.md on every start/build, with an intro explaining the notes are unreleased and how to try them, plus the categorized notes list. - Wire the generator into the docs start/build scripts, add a sidebar entry next to Release Notes, and gitignore the generated page. https://claude.ai/code/session_01MuY9Phome8uJKH51HbrsQw * [AI] Simplify upcoming-release-notes generator - Declare @actual-app/ci-actions as a workspace dependency and import the shared util by package name instead of a relative cross-package path, so the dependency is registered in the workspace graph. - Resolve the repo root once via new URL() and drop the dirname import. - Use a ternary for the page body instead of let + if/else. https://claude.ai/code/session_01MuY9Phome8uJKH51HbrsQw * Add release notes for PR #8065 * [AI] Remove edge references, keep only nightly in docs Co-authored-by: Matiss Janis Aboltins <[email protected]> * Update packages/docs/scripts/generate-upcoming-release-notes.mjs Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Cursor Agent <[email protected]> Co-authored-by: Matiss Janis Aboltins <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * Bump the npm_and_yarn group across 2 directories with 1 update (#8071) Bumps the npm_and_yarn group with 1 update in the / directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Bumps the npm_and_yarn group with 1 update in the /packages/desktop-client directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Updates `react-router` from 7.13.1 to 7.14.2 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) Updates `react-router` from 7.13.1 to 7.14.2 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) --- updated-dependencies: - dependency-name: react-router dependency-version: 7.14.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: react-router dependency-version: 7.14.2 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * When resetting SimpleFIN credentials, parse error and error_code if response body exists (#8068) * Initial commit * Add release note * Update release note file name to match PR number * Flip operands when checking for 2xx * Release notes grammar * Better release note for non-devs * Simplify to naive solution of checking on nullable response * Hiding tags and tag table bulk actions (#7919) * [AI] Make TypeScript work in test files across packages Match the CRDT package's tsconfig pattern in loot-core, desktop-client, api, and desktop-electron so test files participate in the project graph (IDE intellisense, project-wide typecheck) while production builds still emit clean declaration files. - Remove test-file exclusions from each package's main tsconfig - Add tsconfig.build.json for loot-core and api with test exclusions, used by the build scripts - Add e2e/tsconfig.json for desktop-client and desktop-electron with Playwright types - Fix latent type errors in test files now caught by typecheck - Disable typescript/unbound-method for test files (mock matcher pattern) Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Address review feedback on test type fixes - goal-template.test.ts: extract amounts to typed locals so single-value assertions no longer compare against unknown - category-template-context.test.ts: replace `as unknown as DbCategory` double-cast with a fully-typed object using `satisfies DbCategory` (the previous mock had `is_income: true` which doesn't match the `1 | 0` shape the cast was hiding) - api/tsconfig.build.json: broaden test exclude pattern to `**/*.test.ts` Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Drop tsconfig.build.json for loot-core and api The build-config indirection was incomplete protection: typecheck (`tsgo -b` against the main tsconfig, which now includes test files) already emits `*.test.d.ts` into `@types/`, and the build step does not clean before re-emitting. The same is observable in crdt's `dist/`, which currently contains test declarations on disk. What actually keeps test declarations out of the npm tarball is the `files` field in package.json — and loot-core already uses that mechanism for source files (`\!src/**/*.test.ts`). Extending the same pattern to `@types/` is more direct than maintaining a duplicate tsconfig that doesn't reliably do its job. - Delete loot-core/tsconfig.build.json; revert build to `tsgo -b`; add `\!@types/**/*.test.d.ts*`, `\!@types/**/__tests__/**`, `\!@types/**/__mocks__/**` to `files`. - Delete api/tsconfig.build.json; revert build to `vite build && tsgo --emitDeclarationOnly`; add `\!@types/**/*.test.d.ts*` to `files`. Verified: `yarn pack --dry-run` excludes all test declarations from both packages while production declarations still pack (428 .d.ts files for loot-core, methods.d.ts for api). Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * first pass at implementation * finished implementing what I feel would be a good user experience * padding update * added ability to use tab to select * release notes * updated release notes * auto highlights first entry * removed debug info * linting formatting * updated behavior with tags in the middle of stuff * minor improvements to ux * extracted TagAutocomplete functionality into its own file * rewrote TagAutocomplete using react-aria-components from scratch * linting * restored old autocomplete since I'm no longer using it * linting * capped results at 10 * bugfix * used tag css hook instead of notes tag formatter * added mobile support * fixed bug where inserting a tag at the end of the note wouldn't fire onChange handler * fixed bug where note would hover even though field was not focused * fixed bug with currentWord detection * some more minor UI bugs with the mobile UI * removed log statement * added aria-label * [autofix.ci] apply automated fixes * name to Input * updatedt ests * fixed tests * whitespace adjustment * removed debug from test * added tests and made a few fixes * tried to fix vrt * some new hooks to use * removed log statement * removed input from useCursorPosition * input ref value hook now triggers on mount * add extra padding * hide browser autocomplete when our popup is shown to avoid doubles * useFilteredTags hook and adjustments to mobile tag UI * switched from opacity to height transitioning * sorted filtered tags by startsWith first * updated highlighting logic for mouseover * [autofix.ci] apply automated fixes * fix tag ordering * button type * [autofix.ci] apply automated fixes * release note update * release note to trigger ci * reverted db change * Revert "reverted db change" This reverts commit 24ce5450e5e4261e77fe5056620c240da22869a3. * can now filter by tags without hashes * extracted a method and added a new hasAnyTags rule * added hasAnyTag, still need to figure out why tests are failing * fixed unit tests * release notes * fixed based on coderabbit * tag.toLowerCase() * variable scope fix * fixed some focus-related bugs * allow creating tags in the dropdown for desktop * fixed focus issues with useCursorPosition * added Create Tag functionality to mobile * tests and added some length clipping as qol * can now use enter to submit new tag properly * centralized overflow CSS for tags * centered the text horizontally * added textnowrap * release notes * linting * fixed issue with async keydown handler * specified only to use new tag css for the autocomplete stuff * forgot to add new option to tag table * removed Trans * started working on multiselect * multiselect is now functional * finished multiAutocomplete implementation * [autofix.ci] apply automated fixes * removed double input * added multi autocomplete to rule editor * adjusted padding for TagMultiAutocomplete * adjusted hover cursor * release notes * fixed rule conditions * added tag styling to filter multiselect * spacing adjustment * release notes for retriggering build * added hidden migration * added hidden to models * added tags-hide-all and tags-unhide-all actions * added hide and unhide tags actions * added SelectedTagsButton * added UI elements for hiding/showing tags * release notes * removed delete from ManageTags * added icons to menu * coderabbit * coderabbit * updated mutations for translations * coderabbit * removed not null requirement * attempted to fix tests? * removed duplicate filterTags * [autofix.ci] apply automated fixes * updated release notes * release note update * updated migration timestamp * moved tags menu button --------- Co-authored-by: github-actions[bot] <[email protected]> Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: Alec Bakholdin <alecbakholdin.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * automation UI: improve scaling (#8080) * improve scaling on high zoom levels * note * automation UI: rework balance cap and fix error when clearing fields (#8082) * fix safeNumber error * rework balance cap UI to be more readable * note * add explanation to balance cap * Bump react-router in the npm_and_yarn group across 1 directory (#8072) Bumps the npm_and_yarn group with 1 update in the / directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Updates `react-router` from 7.14.2 to 7.15.0 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) --- updated-dependencies: - dependency-name: react-router dependency-version: 7.15.0 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * [AI] feat(currencies): add currency-precision-aware helpers (#8064) * [AI] feat(currencies): add getDecimalPlaces/getCurrencyPrecisionMultiplier helpers, encodeAmount, currency-aware integerToCurrencyWithDecimal * Fix typo in release note * Use it.each in unit tests * Rename encodeAmount and replace its body; remove getCurrencyPrecisionMultiplier * [AI] Remove AI-generated release notes workflow and support custom filenames (#7963) * [AI] Relax release-notes filename convention Allow descriptive filenames (e.g. add-payee-autocomplete.md) for upcoming release notes instead of requiring {PR_NUMBER}.md. The PR number was only used to build the [#1234](.../pull/1234) link in the generated changelog. The generation script now resolves the PR per file by finding the commit that added it (git log --diff-filter=A --follow) and querying GitHub's commits/{sha}/pulls endpoint. Numeric filenames remain valid via a fast path. Also retires the CodeRabbit/OpenAI-triggered auto-creator workflow, which existed to guess summaries and stamp the PR-numbered filename; neither is needed once contributors can pick a slug up front. * Add release notes for PR #7963 * [AI] Use execFile to look up release-note add-commits resolvePrNumber() interpolated a path from fs.readdir into a shell- evaluated `git log` command. Switch to execFile with an argv array so filenames containing shell metacharacters can't break out of the intended command. * [AI] Drop duplicate release note added by the to-be-removed auto-creator The CodeRabbit-triggered workflow ran one last time from master before this PR removes it, and committed upcoming-release-notes/7963.md duplicating the existing relax-release-notes-filenames.md entry. Keep the slug-named note since it exercises the new flexible-filename code introduced in this PR. * [AI] Don't fail release-notes generation on transient API errors fetchPrForCommit() handled non-OK HTTP responses but let fetch() and res.json() exceptions propagate, so a single network blip or malformed response would abort the whole release-notes generation. Wrap them in a try/catch that logs and returns null, matching the pattern already used in resolvePrNumber for execFile errors. * [AI] Address CodeRabbit full-review nits - bin/release-note-generator.ts: tighten slug regex to reject trailing and consecutive dashes (matching slugify output), and make slugify fall back to "untitled" so an all-non-alphanumeric input can't produce a hidden ".md" filename. - packages/ci-actions/bin/release-notes-check.mjs: switch to execFile for git fetch/diff, matching release-notes-generate.mjs and removing shell interpolation of BASE_REF. - packages/ci-actions/bin/release-notes-generate.mjs: explicitly check GITHUB_REPOSITORY before splitting, consistent with the other env var guards a few lines below. - upcoming-release-notes/relax-release-notes-filenames.md: fix author casing (matiss -> MatissJanis) so changelog attribution is correct. * [AI] Reject empty release-note bodies content.trim().split('\n').length === 1 is true for the empty string (''.split('\n') returns [''] of length 1), so blank notes slipped past the single-line check. Reject empty trimmed content explicitly. * [AI] Resolve PR numbers from commit subjects instead of GitHub's API parseReleaseNotes was doing one GitHub API round-trip per non-numeric release-note file. That scales badly for release generation, and the docs site's generate-upcoming-release-notes.mjs runs on every docs build — so contributors were hitting the GitHub API (or failing 401 without a token) every time they previewed docs locally. actualbudget squash-merges every PR through the GitHub UI, which appends "(#NNNN)" to the resulting commit subject. So: git log -1 --format=%s -- <path> plus a /\(#(\d+)\)\s*$/ match recovers the PR number without touching the network, and works offline / without a GITHUB_TOKEN. Side effect: switched from "first commit that added this file" to "most recent commit touching this file", which is what we actually want — when a file is renamed (e.g. 7907.md -> 7954.md when a wrong PR number is corrected), the changelog should point at the rename PR, not the original add. The SHA->PR cache and fetchPrForCommit go away; no longer needed. If a file's subject doesn't match (direct push to master, manually rewritten subject), the entry still emits without a PR-link prefix — same graceful degradation as before. * [AI] Pin PR-number lookup to each note's add commit resolvePrNumber was using git log -1 with no diff filter, returning the latest commit that touched the file. That's fine until someone edits an existing release note in a follow-up PR (typo fix, author correction) — at which point the changelog entry would suddenly point at the wrong PR. Add --diff-filter=A so the lookup pins to the commit that originally added the path. Empirically verified against this repo: renames keep working (git records a rename as A at the new path when --follow isn't used), and the edit case now correctly returns the original add commit instead of the most recent touch. --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Add GitHub workflow to block PRs with "do not merge" label (#8090) * [AI] Add CI job that fails when 'do not merge' label is set * [AI] Rename do not merge check job to "Block PRs with do not merge label" * [AI] Rename do not merge workflow to "Block PRs with do not merge label" * [AI] Add release notes for do not merge CI check * Update 8090.md --------- Co-authored-by: Claude <[email protected]> * [AI] Persist bank sync status in the accounts table (#8017) * [AI] Persist bank sync status in the accounts table Extracts the persisted bank-sync-status half of #7782 (by @jcam): adds a bank_sync_status column to the accounts table, writes the status (pending/ok/failed/reauth-required/attention-required) during native bank syncs, and reads the persisted value in the UI (sidebar, account header, mobile account pages, and the sync banner) instead of ephemeral Redux state. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Add release note for persisted bank sync status https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Persist only durable failure states, keep pending ephemeral Addresses review feedback: a transient 'pending' write could get stuck in the DB (and propagated via CRDT) if the app closed mid-sync. The DB now only stores durable result states (ok / failed / reauth-required / attention- required); pending stays in ephemeral Redux state (account.accountsSyncing) as before. The UI reads only the persisted failure state via isAccountFailedSync, and the BankSyncStatus banner reverts to the ephemeral in-flight count. Also extracts a persistBankSyncError helper and inlines a redundant wrapper. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Un-export AccountSyncSidebar, refine release note - AccountSyncSidebar is internal again; drop the export-only-for-test and its test (the failure logic is already covered by syncStatus.test.ts). - Credit MatissJanis in the release note and make it user-centric. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Publish account changes in bank-sync sync-events handleSyncResponse writes accounts.last_sync and accounts.bank_sync_status, but the sync-events following it only declared tables: ['transactions'], so clients only refetch useAccounts when the event includes 'accounts'. Add 'accounts' to the six emissions that follow handleSyncResponse (the four link flows and the two batch-sync finals) so the persisted account changes are published everywhere, not just on the triggering client. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Re-timestamp bank_sync_status migration after master A newer migration (add_tags_hidden) landed on master, so bump the bank_sync_status migration's timestamp to remain the latest and satisfy the migration-ordering check. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD --------- Co-authored-by: Claude <[email protected]> * Remove environment from release notes workflow (#8091) * Remove environment from release notes workflow Removed the environment specification from the release notes workflow. * Update release-notes CI job configuration Removed the unnecessary 'environment' from the release-notes CI job. * [AI] Enable "do not merge" check on merge queue events (#8092) * [AI] Run do-not-merge check on merge_group events The block-do-not-merge workflow only triggered on pull_request events, so it never ran in the merge queue and could not be made a required check. Adding the merge_group trigger lets the job run and pass in the queue context (where pull_request labels are absent), allowing it to be required. * [AI] Add release notes for merge queue do-not-merge fix --------- Co-authored-by: Claude <[email protected]> * Make payee & categories searching to be case-insentive (#8079) * make payee & categories searching to be case-insentive * add release notes * [autofix.ci] apply automated fixes * Update VRT screenshots Auto-generated by VRT workflow PR: #8079 * update release-note * [autofix.ci] apply automated fixes * fix release-note format --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Add files via upload (#8096) * [AI] Fix incorrect schedule value when saving full amount (#8085) If one has a yearly schedule and the budget template uses "Cover each occurence when it occurs", it still showed a value for the yearly schedule even though it's not the month where the schedule occurs. Co-authored-by: Gemini <[email protected]> * feat: add SharedArrayBuffer warning indicator in title bar (#7922) * feat: add SharedArrayBuffer warning indicator in title bar * improve styling * add warning label * fix typo * review comments fixed * use link instead of button * fix tooltip styles * add hover effect --------- Co-authored-by: Awais Saeed <[email protected]> * [AI] Remove experimental status from Actual CLI (#8102) * [AI] Move actual-cli out of experimental status * [AI] Rename CLI release note to a feature slug --------- Co-authored-by: Claude <[email protected]> * add warning when schedule/save by automation priorities don't match (#8088) * add warning when schedle/save by automation priorities don't match * note * italicise * feat(reports): scoped ErrorBoundaries for individual report routes (#7658) * feat(reports): scoped ErrorBoundaries for individual report routes (#7391) Wrap each route in ReportRouter for NetWorth, CashFlow, Spending, etc. in ErrorBoundary with FeatureErrorFallback. Matches the pattern used for /rules routes in FinancesApp.tsx so a render error in a single report no longer takes down the whole app. * chore: rename release note to PR number * refactor(reports): extract withReportBoundary helper to remove route boilerplate Each report route was wrapping its element in the same ErrorBoundary block with FeatureErrorFallback and resetKeys={[location.pathname]}. Pull that into a small withReportBoundary(element) helper inside ReportRouter so each route is one line again. Behavior is unchanged. The ErrorBoundary, FallbackComponent, and resetKeys are identical to before; the helper just closes over location.pathname. Addresses review feedback from @joel-jeremy and the CodeRabbit nitpick on the same file (a custom Route component is not viable since react-router v6's <Routes> requires literal <Route> children, but a helper function gives the same boilerplate reduction). * refactor(reports): hoist withReportBoundary to ReportBoundary component Move the per-route error-boundary helper out of ReportRouter as a module-scoped component. ReportBoundary calls useLocation() internally so each call site stays clean. Addresses review feedback. --------- Co-authored-by: github-actions[bot] <[email protected]> Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Add configurable average ranges to Monthly Spending report (#7920) * Add configurable average ranges to Monthly Spending report * Delete upcoming-release-notes/temp.md * Update packages/desktop-client/src/components/reports/spendingAverageRange.test.ts Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Fix spending average range test import * Update VRT screenshots Auto-generated by VRT workflow PR: #7920 --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: youngcw <[email protected]> * [AI] Fix custom report transfer drilldown filters (#8001) Co-authored-by: youngcw <[email protected]> * Make tag search case-insensitive (#8093) * makes tags case insensitive * release notes --------- Co-authored-by: Alec Bakholdin <alecbakholdin.com> * docs: add Hostim to Additional Installation Options (#8066) * docs: add Hostim to community install options Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * docs: add release note for #8066 Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * docs: drop release note (not required for docs-only change) --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> Co-authored-by: youngcw <[email protected]> * [AI] Add SSRF protection to SimpleFIN bank sync integration (#8012) * [AI] Add SSRF protection to SimpleFIN bank sync integration The SimpleFIN integration made server-side HTTP requests to user-controlled URLs (the base64-encoded claim token and the resulting access-key base URL) without any validation, unlike the CORS proxy which blocks private IPs via ipaddr.js. Add a shared assertUrlAllowed() helper that rejects non-http(s) URLs and blocks requests to private, loopback, link-local, unique-local, reserved, broadcast and unspecified addresses. Hostnames are resolved via DNS so names pointing at internal addresses are blocked too, not just literal IPs. Apply it before both outbound requests in getAccessKey() and getAccounts(). * [AI] Unify CORS proxy private-IP check with shared SSRF helper The CORS proxy had its own inline ipaddr.js private-IP check that duplicated the logic in the SimpleFIN SSRF helper. Export isBlockedIp() from util/ssrf and reuse it in app-cors-proxy, removing the duplicate. This also widens the CORS proxy's coverage to the reserved and broadcast ranges and normalizes IPv4-mapped IPv6 addresses, matching the SimpleFIN helper. The cors-proxy tests now exercise the real ipaddr.js against real private IPs instead of mocking it. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Rename SimpleFIN SSRF release note to match PR number Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * Implement SSRF protection for SimpleFIN bank sync Requests to private, loopback, link-local, and other internal addresses are now blocked. * [AI] Allow self-hosted private SimpleFIN servers by default The SSRF protection blocked all private/loopback addresses, which broke self-hosters running their own SimpleFIN bridge on a LAN or VPN IP with no way to opt back in. Split the blocked ranges into two tiers: link-local (cloud metadata), reserved, broadcast and unspecified stay blocked unconditionally, while private/loopback/unique-local are blocked by default but can be permitted per-caller via { allowPrivateNetwork: true }. SimpleFIN opts in, so self-hosting works out of the box with no env var, while the worst-case cloud-metadata credential-theft vector remains closed. The CORS proxy keeps the strict default. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Re-validate SSRF rules on each SimpleFIN redirect hop getAccounts used fetch with redirect: 'follow', so a 3xx response from the validated SimpleFIN URL could redirect to a blocked internal address after only the initial URL had been checked. Follow redirects manually instead, calling assertUrlAllowed on every hop before fetching, capping at 5 redirects, and dropping Authorization on cross-origin hops so the bridge credentials cannot leak to a redirect target. getAccessKey uses https.request, which does not auto-follow redirects, so it is unaffected. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> --------- Co-authored-by: Claude <[email protected]> * [AI] Skip unimportable Enable Banking transactions instead of failing the whole sync (#8086) * [AI] Skip unimportable Enable Banking transactions instead of failing the whole sync Enable Banking bank-sync aborts the whole account import with a client-side SQLITE_ERROR when a fetched transaction cannot be inserted — most commonly a pending transaction with no booking/value/transaction date (normalized to date ''), or a non-numeric amount. Add an isImportableTransaction helper and skip such records in the /transactions handler (logging the count) so the rest of the account imports. Dated pending transactions are unaffected. * [AI] Add release note for #8086 * [AI] Reject empty Enable Banking transaction amounts Number('') is 0 (finite), so an empty/whitespace amount slipped through isImportableTransaction as a zero transaction. Trim and reject empty amounts explicitly, with a test. Addresses PR review feedback. * Update packages/sync-server/src/app-enablebanking/services/enablebanking-service.ts Co-authored-by: Matiss Janis Aboltins <[email protected]> * Update packages/sync-server/src/app-enablebanking/app-enablebanking.ts Co-authored-by: Matiss Janis Aboltins <[email protected]> * [AI] Remove now-unused skippedCount counter The summary log that read it was removed when accepting the review suggestion; drop the dangling write-only counter so the loop matches the per-transaction skip log that remains. --------- Co-authored-by: Matiss Janis Aboltins <[email protected]> * [AI] Disable ESLint in CodeRabbit configuration (#8110) * [AI] Disable ESLint in CodeRabbit config * [AI] Add release notes for CodeRabbit ESLint change * [AI] Rename release notes to match PR number 8110 * [AI] Rename release notes file to a slug --------- Co-authored-by: Claude <[email protected]> * Feature: Add Akahu New Zealand bank sync (#6041) * add akahu integration for nz banks * akahu fix bank name being set to account name * rename apiToken and fix reset pointing to the wrong function * fix apitoken wording in akahu init modal * add upcoming-release-notes * fix lint issues * fix lint issues * add loan account type to starting balance inversion * fix initial sync balance * initially select 365 days of transactions on first sync for akahu sync * add SyncServerAkahuAccount to onSetLinkedAccount * set transaction currency to account currency * remove unnecessary code * handle TFR TO/FROM payees and account for loan account type in transactions * [autofix.ci] apply automated fixes * rename Error to ErrorAlert and fix intial sync start date * extract note from description for TFR TO/FROM transactions * fix normalizeNotes not referencing the transaction * refactor app-akahu code * [autofix.ci] apply automated fixes * Add Akahu to ExternalAccount type * Update yarn.lock * update yarn.lock * Remove unused error var in catch block * [autofix.ci] apply automated fixes * require authentication for akahu endpoint * fix lint issue in mutations.ts * fix up import paths * fix lint issues * reorder form fields * remove unnecessary handling for debt accounts * lint fixes * Put Akahu bank sync under feature flag * remove incorrect feedback link * [autofix.ci] apply automated fixes * Add feedback link for feature toggle * use uuidv4 * prevent fetch if feature not enabled * change app-akahu to ts and tidy up * fix typecheck errors * [autofix.ci] apply automated fixes * fix browser client build issues * [autofix.ci] apply automated fixes * update akahu npm package to latest version * use amountToInteger for balance reducer * add additional details to transactions * change initial sync start date logic * add akahu fields to mappable fields in desktop-client * [autofix.ci] apply automated fixes * getDate use formatISO to get the timezone adjusted date * remove duplicate payeeName --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * automation UI: add mobile support 📱 (#8099) * generalise out to hooks * add mobile modal * wire up mobile * tidy up field styling on mobile * [AI] add mobile automations e2e test Covers opening the editor from the mobile category menu, the drill-down list/editor navigation, touch-sized fields, and that Cancel dismisses it. Co-Authored-By: Claude Opus 4.8 <[email protected]> * note * Update VRT screenshots Auto-generated by VRT workflow PR: #8099 * fix date picker on schedule page * fix conflict * fix cramped space in save by automation --------- Co-authored-by: Claude Opus 4.8 <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [Docs] Starting at the top, Introduction & Vision (#8083) * Enhance introduction and navigation details in docs Revised wording for clarity and improved navigation instructions in the documentation. * Update vision.md for clarity and formatting Refine language for clarity and consistency, and update formatting for better readability. * Improve formatting of third-party use section Reformatted the third-party use section for clarity. * Revise documentation introduction and navigation details Updated the introduction and navigation instructions for clarity and conciseness. * Revise documentation overview and navigation details Updated documentation for clarity and navigation instructions. * Refine Local-first explanation in vision.md Removed redundant text in the Local-first section. * [autofix.ci] apply automated fixes * Revise contribution guidelines in documentation Updated links to contributing guides and documentation readme. * Revise headings and improve hyphenation in vision.md Updated headings and corrected hyphenation in vision.md. * [autofix.ci] apply automated fixes * Fix wording in contribution guidelines section Corrected the wording from 'documentation standard' to 'documentation standards' for clarity. --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matiss Janis Aboltins <[email protected]> * [AI] Fix bank sync deadlock from nested mutator (#8111) * [AI] Fix bank sync deadlock from nested mutator PR #8017 wrapped the accounts-bank-sync and simplefin-batch-sync handlers in mutator(). runHandler runs mutators via runMutator, which is sequential() — only one mutator may run at a time and re-entrant calls are queued. These handlers call syncAccount -> reconcileTransactions, which already invokes runMutator internally. The inner runMutator gets queued behind the still-running outer one while the outer awaits it, deadlocking forever. The bank sync send() never resolves, so the mobile spinner spins indefinitely. Remove the mutator() wrapping (restoring pre-#8017 registration). The DB writes for bank_sync_status/last_sync already ran outside a mutator before #8017, and transaction reconciliation manages its own mutator context. * [AI] Add regression tests for bank sync mutator deadlock Guards against re-wrapping the accounts-bank-sync / simplefin-batch-sync handlers in mutator(), which deadlocks because the sync internally calls runMutator (reconcileTransactions) and runMutator is sequential. - An invariant test asserts neither handler is a mutating method. - A behavioral test drives accounts-bank-sync through runHandler with a syncAccount mock that performs its own runMutator, and fails via a timeout if the nested mutators deadlock. * [AI] Simplify deadlock regression test Collapse the two-step Promise.race into a single race result and clear the timeout timer on the success path so it doesn't linger after the test. * [AI] Remove explanatory comments from deadlock regression test * [AI] Add release note for bank sync deadlock fix * Update packages/loot-core/src/server/accounts/app-bank-sync.test.ts Co-authored-by: Matt Fiddaman <[email protected]> * Update packages/loot-core/src/server/accounts/app-bank-sync.test.ts Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: Claude <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * [AI] Fix desktop settings resetting after an interrupted update (#8101) * [AI] Fix desktop settings resetting after an interrupted update Desktop global prefs (language, theme, etc.) live in a single global-store.json that was written non-atomically and silently reset to {} whenever it failed to parse. An app update's forced quit can truncate the file mid-write, so the next launch wiped every global pref - the language reverted to "System default" (the OS language). - Write the store via a unique temp file + atomic rename so it is never left half-written. - Serialize writes so a slower older write can't land after and clobber a newer one. - Back up an unparseable store to .corrupt and log loudly instead of silently discarding the user's preferences. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Reject non-object global-store contents during load JSON.parse could return a non-object (null, an array, a primitive) for parseable-but-wrong-shaped contents, which would then break store[key] access. Validate the parsed value is a plain object and route anything else through the existing back-up-and-default recovery path. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * :electron: Removed new shared array buffer warning on Electron (#8118) * removed shared array buffer warning one electron * release notes * cleanup a bit * Enhance translation contribution guidelines in i18n.md (#8113) * Enhance translation contribution guidelines in i18n.md Updated i18n.md to include new guidelines for contributing translations, account requirements, and voting on suggestions. * Update i18n.md * [AI] update contributor guidelines for AI usage (#8135) * [AI] Surface anti-slop and self-review expectations at PR time Drive-by, LLM-generated PRs (often many at once from one author) burn maintainer review time. The repo's AI usage policy already covers this, but contributors never see it in the PR flow. - Strengthen the fork-PR welcome comment to ask for a human self-review confirmation, a plain-language testing note, and AI disclosure, plus a note discouraging opening many PRs at once. - Add a "Quality Over Quantity" section to the AI usage policy naming the volume pattern and its consequences. - Add an AI-disclosure prompt and tighten the self-review item in the PR template. No mechanical CI gates on PR body content: those are trivially satisfied by the same tools that generate the slop, so the change relies on human accountability and a linkable policy instead. * [AI] Point welcome comment at the PR template instead of inline asks Replace the three "reply on this PR with" bullets with a single checklist item asking contributors to use the PR template and fill in its checkboxes, keeping the welcome comment short. * [AI] Add AI disclosure checklist item to fork PR welcome comment --------- Co-authored-by: Claude <[email protected]> * [AI] Fix CLI server version without open budget (#8117) * [AI] fix cli server version without open budget * Remove redundant expectation in get-server-version test Remove redundant expectation for get-server-version handler call. --------- Co-authored-by: Matiss Janis Aboltins <[email protected]> * [AI] Skip posted schedule occurrences in balance forecast (#8029) * [AI] Extract schedule occurrence match start date helper Centralize the lower-bound rules for matching posted transactions to schedule dates and reuse them in getHasTransactionsQuery, including the correct 2-day lookback for recurring schedules stored with op is. * [AI] Add schedule occurrence posted matching helpers Add isScheduleOccurrencePosted with the match-start logic built in and indexPostedScheduleTransactions for efficient per-schedule lookups. * [AI] Skip posted schedule occurrences in balance forecast Skip synthetic schedule occurrences when a posted transaction already covers that date, using indexed per-schedule lookups in the forecast path. * [AI] Add release notes for balance forecast schedule dedup fix * [AI] Treat op is schedule dates as exact match start Restore master semantics: recurring schedules with op is use exact occurrence matching, not a 2-day lookback. Remove conflicting tests. * [AI] Add daily recurring forecast dedup regression test Prove daily schedules with op is do not double-count when posted on the due date, while subsequent occurrences are still forecast. * [AI] Move browser web-worker logic into loot-core (#8143) * [AI] Move browser web-worker logic into loot-core Relocate the browser Web Worker bootstrap (WorkerBridge + startBrowserBackend) and the multi-tab SharedWorker coordinator from desktop-client into loot-core so they can be reused (e.g. by the api package in a browser). Behavior is preserved as faithfully as possible. The two Vite worker entry targets stay in desktop-client (the browser-server.js classic worker and the ?sharedworker entry); the ?sharedworker entry now imports the coordinator from loot-core. console.* calls in the moved code route through loot-core's logger, except the SharedWorker console-forwarding mechanism, which must keep the real console. absurd-sql's initBackend is imported directly (loot-core already depends on absurd-sql); the desktop-client dependency was dropped. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Rename release note to match PR number 8143 * Update release notes for Web Worker migration Removed mention of reuse by the API package in the release notes. * [AI] Drop move-related header comments per review Remove the "moved from desktop-client" header comments that only made sense in the context of this PR. worker-bridge.ts and start.ts had no header comment in the original source, so they're removed entirely; coordinator.ts's header is restored to its original wording. --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * Refresh akahu account if stale (#8115) * Refresh akahu account if stale * Update upcoming-release-notes/akahu-refresh.md * wait for the refresh to complete * check account is defined * use local variable * move into helper * increase poll delay * bump refresh interval to 1 hour * ensure only one account refresh is running at a time * [AI] Drop ACTIONS_UPDATE_TOKEN from release workflows (#8142) * [AI] Drop ACTIONS_UPDATE_TOKEN from release workflows Replace the implicit push-triggers-workflow link (which relied on the ACTIONS_UPDATE_TOKEN PAT) with an explicit workflow_run chain from "Cut release branch" to "Release notes", falling back to the built-in GITHUB_TOKEN. The PAT stays in vrt-update-apply.yml, which genuinely needs it to push to contributor forks and re-trigger their PR CI. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Add release note for ACTIONS_UPDATE_TOKEN removal Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * Update 8142.md --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Consolidate agent tooling and simplify developer guidance (#8089) * [AI] Replace mechanical agent rules with shared agent hooks + nano-staged Move the mechanical "remember to run X" rules out of AGENTS.md and the agent guidance docs into deterministic, cross-agent hooks, and migrate the pre-commit runner from lint-staged to nano-staged. - Add shared hook scripts in scripts/agent-hooks/ (git-guard, format-edited-file, no-strict-ignore-new-file, prefer-one-component, check-on-stop, common helpers) wired for Claude (.claude/settings.json), Codex (.codex/config.toml), and Cursor (.cursor/hooks.json + adapters). - Enforce "avoid enum" via a new actual/no-enum lint rule, grandfathering the two existing declarations in .oxlintrc.json overrides. - Migrate lint-staged -> nano-staged (.nano-staged.json, .husky/pre-commit, package.json). - Trim AGENTS.md, .github/agents/pr-and-commit-rules.md, the Cursor rule, and the committing skill down to the rules that aren't auto-enforced. - Add release note 8089.md. * [AI] Align PR-title wording in AGENTS.md with canonical rules * [AI] Fix check-on-stop hook on bash 3.2 and TSV column collapse The Stop hook silently no-op'd in two ways: - `declare -A` isn't supported on stock macOS bash 3.2, and the slash/hyphen path subscript aborted under `set -u`. Dedupe via a space-padded string match instead. - jq emitted an empty middle TSV field for a package with test but no typecheck; tab is IFS-whitespace so `read` collapsed it and shifted the columns (eslint-plugin-actual then ran neither). Emit non-empty sentinels (-, yes/no) so no field can collapse. Co-Authored-By: Claude Opus 4.8 <[email protected]> --------- Co-authored-by: Claude <[email protected]> * [AI] docs(migration): expand nYNAB export with tabbed alternatives (#8155) Add CLI tool (ynab-export), YNAB API Documentation UI, and cURL as fallback export methods for when the third-party web exporter is unavailable. Converts nynab.md to MDX to support Docusaurus Tabs. Six new screenshots added for the API Documentation UI method. * Add Enable Banking PSU type selection (#8028) * Add Enable Banking PSU type selection * [autofix.ci] apply automated fixes * Add release note for Enable Banking PSU type selection --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> * [AI] fix: translate transfer menu empty placeholder (#8161) * fix: translate transfer menu empty placeholder * docs: add release note for transfer placeholder fix * [AI] fix release note category * [AI] Add missing widget types to dashboard import validation (#8159) * [AI] Add missing widget types to dashboard import validation * [AI] Add test ensuring all widget types are covered by import validation * [AI] Add release notes for dashboard import widget type support * [AI] fix: clear split parent payee (#8005) Co-authored-by: Matiss Janis Aboltins <[email protected]> * Fix Sankey Budgeted view, when an amount is left to budget. (#8169) * Fix Budget view, when an amount is left to budget. * Add translation to To budget-node * docs: fix docs build & broken anchors, migrate to consistent link format (#8173) * fix broken anchors * enable build fail on broken anchors * move to relative links * Update check-spelling metadata * update style guide to match * coderabbit * [AI] docs: fix broken blog links and add enforce-doc-links remark plugin (#8180) * [AI] docs: fix broken blog links and add enforce-doc-links remark plugin - Fix three docs/ pages that linked to blog posts using URL slugs instead of file paths, with an extra ../ level in the relative path - Add src/remark/enforce-doc-links.js: remark plugin that enforces link hygiene in docs/ and blog/ at build time (no absolute internal links, .md extension required, slug-style links caught via frontmatter cache) - Upgrade onBrokenMarkdownLinks from 'warn' to 'throw' so broken .md file-path links fail the build rather than being silently ignored * [autofix.ci] apply automated fixes * [AI] docs: add vfile to spell-check allowlist * [AI] docs: fix build failures from cross-plugin and absolute links - Revert docs→blog links to URL-slug style (Docusaurus cannot resolve .md file paths across content plugins — blog is a separate plugin from docs) - Fix absolute /docs/... links in two blog posts to relative URL form - Fix generate-upcoming-release-notes.mjs hardcoded /docs/releases absolute URLs to relative ./releases.md paths - Update enforce-doc-links plugin: exempt docs→blog URL-slug links from Rule 3 (cross-plu…
jtbandes
added a commit
to foxglove/mcap
that referenced
this pull request
Aug 3, 2026
shawalli
added a commit
to shawalli/actual
that referenced
this pull request
Aug 4, 2026
* 🔖 update release branch (#8565) * fix schedule modal scrollbars (#7992) * [AI] Custom highlight for added sync items: transaction table and sidebar (#7998) * Add new CSS variables for text items in dark theme * Add new CSS variables for table and sidebar items * Add new CSS variables for table and sidebar items * Update sidebar account style for updated state * Enhance valueStyle with color for added items * [autofix.ci] apply automated fixes * Add new theme variables for table and sidebar * Add color variables to added sync items Add color variables for enhanced visibility of items. * [AI] Apply added-row styling to transaction notes cell Co-authored-by: Cursor <[email protected]> --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Cursor <[email protected]> * Add Pakistani PKR currency (#7993) Co-authored-by: Awais Saeed <[email protected]> * add trend line to line graphs (#7954) * add trend line to line graphs * note * add to options * split trend generation logic into seperate handler, add test * tighten types * Goal Templates keyboard shortcut (#7912) * add shortcut * note * change shortcut to ctrl-t * shift t * [AI] Add npm minimal age gate for supply-chain defense (#8011) * [AI] Add npmMinimalAgeGate to block dependency versions newer than 3 days * [autofix.ci] apply automated fixes * [AI] Add release notes for npm minimal age gate --------- Co-authored-by: Claude <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * Add initial docs for Enable Banking (#7961) * Add initial docs for Enable Banking * Delete upcoming-release-notes/7961.md * [AI] Fix docusaurus docs build (#8018) * [AI] Fix docs build by pinning webpackbar to v7 webpack 5.106+ removed deprecated ProgressPlugin options, which breaks the older webpackbar 6.0.1 that Docusaurus 3.10.0 depends on. The build fails with "Progress Plugin has been initialized using an options object that does not match the API schema" (unknown properties name/color/ reporters/reporter). Add a webpackbar ^7.0.0 resolution, matching the upstream fix in Docusaurus 3.10.1 (facebook/docusaurus#11981). * Add release notes for PR #8018 --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * add EB docs to sidebar (#8019) * 🔖 (26.6.0) (#7947) * 🔖 (26.6.0) * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * Update check-spelling metadata * Generate release notes for v26.6.0 * add release summary * links * Generate release notes for v26.6.0 * update links * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * Generate release notes for v26.6.0 * add EB link * Add initial docs for Enable Banking (#7961) * Add initial docs for Enable Banking * Delete upcoming-release-notes/7961.md * [Docs] UI Budget automations & month-end cleanup (#7863) * Add files via upload * Create documentation for budget automation feature Added documentation for the budget automation feature, detailing its functionalities, usage, and examples. * Add files via upload * Revise budget automation documentation for clarity Updated the documentation for budget automation, enhancing clarity and consistency in the descriptions of features and options. * [autofix.ci] apply automated fixes * Update Markdown headers for budget automation section * Add files via upload * Improve formatting in budget automation documentation Updated formatting and added line breaks for better readability in the budget automation documentation. * [autofix.ci] apply automated fixes * Fix HTML line breaks in budget-automation.md Updated HTML line breaks from '</br>' to '<br>' in budget automation documentation. * Fix HTML line breaks in budget automation documentation * Fix headings and formatting in budget-automation.md Updated formatting and corrected headings in budget automation documentation. * Add budget-automation to sidebar items * Add files via upload * Add files via upload * Revise budget automation documentation Updated budget automation documentation to clarify usage of notes templates and detailed instructions for month-end cleanup processes, including named pools and weight calculations. * [autofix.ci] apply automated fixes * Refactor budget automation documentation for clarity Updated various sections for clarity and consistency, including grammar corrections and improved phrasing. * [autofix.ci] apply automated fixes * Enhance budget automation documentation Updated budget automation documentation with new blog links and improved formatting. * Fix links in budget-automation.md Updated links in the budget automation documentation to remove 'docs' prefix for consistency. * Revise budget automation documentation with updates Updated images and text for budget automation documentation, including corrections and enhancements to clarity. * Improve clarity and add save reminders in budget automation Updated wording for clarity and added reminders for saving work. * Update budget automation documentation for clarity Clarify the process of handling leftover funds in the budget automation script. * [autofix.ci] apply automated fixes * Add 'overfund' and 'overfunded' to spelling expect list * Update spelling expectations by removing 'overfunded' Removed 'overfunded' from the spelling expectations. * Add files via upload * 'overfund' to 'overfunded' First the bot tells me overfunded isn't needed if overfund is there. Now, it tells me that overfunded IS needed. I give up. * Enhance budget automation documentation Added new sections on automation adjustments, moved some sections around, added horizontal separators. * Update images and descriptions in budget automation docs * Add files via upload * Add automation notes section to budget automation docs Added a section on automation notes to document how automations, balance caps, and long-term goals can have associated notes for clarity and tracking. * Add files via upload * Update budget automation examples in documentation * Add files via upload * Apply suggestions from code review Co-authored-by: Matt Fiddaman <[email protected]> * [autofix.ci] apply automated fixes * Add 'unmigrate' to spelling expectations * Improve clarity in budget automation documentation Clarified descriptions for budget automation features and improved wording for better understanding. * Correct spelling of 'unmigrate' to 'Unmigrate' They are the same and github is punking me again. * Clarify automation notes description * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Add files via upload * Fix typos in budget-automation documentation Corrected typos and improved clarity in the budget automation documentation. --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: github-merge-queue <[email protected]> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> Co-authored-by: Mats Nilsson <[email protected]> Co-authored-by: Juulz <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Improve Balance Forecast captions (#7957) * [AI] Add visible low point helper for forecasts * [AI] Show ending balance in forecast report * [AI] Show ending balance on forecast card * [AI] Update balance forecast report snapshots * [AI] Add release note for forecast captions * [AI] API: improve messaging for version/schema mismatch errors (#8026) * [AI] Improve messaging for API version/schema mismatch errors When an outdated client or @actual-app/api connects to a budget whose data uses a newer database schema, sync-apply fails with a cryptic "no such column" error that surfaced as a generic download/sync error. Add a version-mismatch message in getDownloadError/getSyncError, gated on the actual SQLite schema-error signature (no such column/table) so other invalid-schema failures keep their generic messaging and otherwise compatible API versions remain usable. * [AI] Set release note author to MatissJanis * Add release notes for PR #8026 * [AI] Address review: use Vitest globals and remove duplicate release note - Drop the explicit `vitest` import in errors.test.ts and rely on the configured test globals (per CodeRabbit review). - Remove the duplicate 8021.md release note, keeping the PR-numbered 8026.md with the clearer description. * [AI] Avoid i18n in loot-core for schema-mismatch message Return the schema-mismatch error as a plain string instead of going through i18next, and drop the i18next setup from the test. loot-core does not depend on i18n, and this message is surfaced verbatim through the programmatic API. * [AI] Remove unnecessary code comments * [AI] Add missing-meta test for getDownloadError --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Fix typo in Budget Automation math expression (#8035) * Fix typo in Budget Automation math expression * Remove release note --------- Co-authored-by: youngcw <[email protected]> * [AI] docs: update reset-password instructions (#7950) * [AI] docs: update reset-password instructions Clarify the current host-side command and keep the source-checkout workflow documented. Closes #7943 * [AI] docs: keep npm reset path alongside actual-server * Fix CSV import settings reset when skipping end lines (#7827) * [AI] fix(api): prevent navigator crash when loading @actual-app/api in Node.js (#8037) * [AI] fix(api): prevent navigator crash when loading @actual-app/api in Node.js Problem ------- @actual-app/api 26.5.0 and 26.6.0 throw "ReferenceError: navigator is not defined" on import in Node.js environments. The loot-core shared bundle includes three platform variants: platform.ts – browser (references navigator at module load time) platform.electron.ts – Electron/desktop (uses Node.js os module) platform.api.ts – Node.js API (safe constants only) The API vite build uses `resolve: { conditions: ['api'] }` to pick the right variant via the loot-core package imports map (#shared/platform). However, months.ts was importing via a bare relative path (`./platform`) instead of the imports-map alias (`#shared/platform`). Vite's conditions-based resolution does not apply to relative imports, so the build fell back to platform.ts (the browser variant), bundling navigator references that crash at load time. Fix --- Change months.ts to import `#shared/platform` instead of `./platform`. This goes through the loot-core package imports map, which the vite `api` condition resolves to platform.api.ts — the Node.js-safe variant. platform.api.ts was already added to the repo alongside this condition infrastructure (in the same 26.6.0 release) but the months.ts import was missed, leaving the crash in the published package. Testing ------- Added packages/api/platform.test.ts, which imports @actual-app/core/shared/ platform under the `api` vite condition and asserts that isBrowser, isPlaywright and isIOSAgent are all false. This test: - Fails if platform.api.ts is deleted (module not found) - Fails if platform.api.ts is modified to reference navigator (ReferenceError) - Fails if the api vite condition is removed, falling back to platform.ts which throws ReferenceError at import time in Node.js Verified by Kyle Slattery against a live Actual Budget instance via the actual-flow integration tool (https://github.com/lunchflow/actual-flow). * Add release note * Update upcoming-release-notes/8037.md Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Delete packages/api/platform.test.ts --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * [AI] Move i18n usage outside of loot-core (#8027) * [AI] Move i18n usage outside of loot-core loot-core should be platform-agnostic and free of i18n concerns. This moves all user-facing translated string helpers (rule/schedule labels, error formatters) into desktop-client's #util/{rule,schedule,error} modules, while keeping the underlying logic in loot-core. - Headless @actual-app/api error formatters in loot-core now return plain English strings (the API has no i18n runtime). - The persisted "Unknown" institution name and the platform storage alert use plain strings. - Removed the unused i18next dependency from loot-core. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Address review feedback on i18n-out-of-loot-core PR - Wrap switch default arms in blocks to satisfy noSwitchDeclarations (desktop-client and loot-core getDownloadError) - getSecretsError: return a localized generic message instead of leaking the raw backend error token - getRecurringDescription: always separate the weekend annotation so it no longer renders as "Monday(after weekend)"; add test coverage - IndexedDB quota error: surface a typed 'indexeddb-quota-error' event from loot-core and present the localized alert in desktop-client instead of a hard-coded English string - Persist a null bank name (instead of English "Unknown") when the provider reports no institution, and render a localized fallback in the bank sync UI --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Fix Balance Forecast chart colors with custom themes (#8031) * [AI] Use report theme colors for Balance Forecast chart lines * [AI] Add release notes for Balance Forecast custom theme fix * fix react compiler on Windows (#8049) * hmm.. * note * [Docs] Revise fly.io deployment instructions for nightly builds (#8059) * Revise deployment instructions for nightly builds Updated instructions for deploying unstable versions of Actual. * Clarify fly deploy commands in installation guide Updated deployment commands for clarity and added example for nightly version. * [autofix.ci] apply automated fixes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Scope Electron update to v41 (#8044) * Initial plan * Bump desktop Electron runtime to v42.3.0 * Add release notes entry for PR #8044 * Change author from Copilot to MikesGlitch Updated author information in release notes. * Update node-abi mappings to support Electron 42 ABI detection * Address validation feedback for Electron update PR * Add better-sqlite3 Electron 42 patch * Update lockfile for better-sqlite3 patch * Remove better-sqlite patch protocol and target Electron 41 * Align release note with Electron 41.7.1 change * Update better-sqlite3 ranges to ^12.8.0 --------- Co-authored-by: copilot-swe-agent[bot] <[email protected]> Co-authored-by: Michael Clark <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * [Enhancements] Removed regex from excel formula execution (#7990) * Removed regex from excel formula execution * [autofix.ci] apply automated fixes * Surface error for BUDGET_QUERY * code review --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Fix balance forecast report Y-axis label clipping (#8030) * [AI] Fix balance forecast report Y-axis label clipping * [AI] Add release notes for #8030 * docs: add actual-bench to community projects (#8045) * docs: add actual-bench to community projects * [autofix.ci] apply automated fixes * docs: add release note for actual-bench community entry * [autofix.ci] apply automated fixes * fix: address coderabbit comments * fix: remove upcoming release notes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * [AI] Add Sort A to Z / Sort Z to A options to budget category groups (#7831) * [AI] Add Sort A to Z / Sort Z to A options to budget category groups (#7831) * Simplify release notes and apply coderabbitai suggestions * [AI] fix(api): trigger SimpleFin batch sync with a single account (#8052) The condition required more than one SimpleFin account before running batch sync, causing a single SimpleFin account to be skipped entirely. Co-authored-by: Claude Opus 4.6 <[email protected]> * add pikapods desktop warning (#8061) * add pikapods desktop warning * better link * add to spelling list * more spelling * [AI] Fix bug when linking accounts (#8006) Fixes a bug that when selecting Link Account from the account page one has to reselect the same account in the modal even though its prepopulated. Co-authored-by: Gemini <[email protected]> * add MXN peso (#8060) * ♻️ remove unnecessary playwright container pulls to speed up CI (#8067) * don't use playwright where it's not needed * note * [AI] Add auto-generated Upcoming Release docs page (#8065) * [AI] Add auto-generated Upcoming Release docs page Adds a docs page that always reflects the current contents of the repo-root upcoming-release-notes/ directory — the changes that have been merged but not yet published in a stable release (i.e. what ships in the nightly/edge builds). - Extract parseReleaseNotes/formatNotes from the release-notes generator into the shared ci-actions util so both the release generator and the docs build reuse the same formatting. - Add a docs build script that regenerates docs/upcoming-release-notes.md on every start/build, with an intro explaining the notes are unreleased and how to try them, plus the categorized notes list. - Wire the generator into the docs start/build scripts, add a sidebar entry next to Release Notes, and gitignore the generated page. https://claude.ai/code/session_01MuY9Phome8uJKH51HbrsQw * [AI] Simplify upcoming-release-notes generator - Declare @actual-app/ci-actions as a workspace dependency and import the shared util by package name instead of a relative cross-package path, so the dependency is registered in the workspace graph. - Resolve the repo root once via new URL() and drop the dirname import. - Use a ternary for the page body instead of let + if/else. https://claude.ai/code/session_01MuY9Phome8uJKH51HbrsQw * Add release notes for PR #8065 * [AI] Remove edge references, keep only nightly in docs Co-authored-by: Matiss Janis Aboltins <[email protected]> * Update packages/docs/scripts/generate-upcoming-release-notes.mjs Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Cursor Agent <[email protected]> Co-authored-by: Matiss Janis Aboltins <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * Bump the npm_and_yarn group across 2 directories with 1 update (#8071) Bumps the npm_and_yarn group with 1 update in the / directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Bumps the npm_and_yarn group with 1 update in the /packages/desktop-client directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Updates `react-router` from 7.13.1 to 7.14.2 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) Updates `react-router` from 7.13.1 to 7.14.2 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) --- updated-dependencies: - dependency-name: react-router dependency-version: 7.14.2 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: react-router dependency-version: 7.14.2 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * When resetting SimpleFIN credentials, parse error and error_code if response body exists (#8068) * Initial commit * Add release note * Update release note file name to match PR number * Flip operands when checking for 2xx * Release notes grammar * Better release note for non-devs * Simplify to naive solution of checking on nullable response * Hiding tags and tag table bulk actions (#7919) * [AI] Make TypeScript work in test files across packages Match the CRDT package's tsconfig pattern in loot-core, desktop-client, api, and desktop-electron so test files participate in the project graph (IDE intellisense, project-wide typecheck) while production builds still emit clean declaration files. - Remove test-file exclusions from each package's main tsconfig - Add tsconfig.build.json for loot-core and api with test exclusions, used by the build scripts - Add e2e/tsconfig.json for desktop-client and desktop-electron with Playwright types - Fix latent type errors in test files now caught by typecheck - Disable typescript/unbound-method for test files (mock matcher pattern) Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Address review feedback on test type fixes - goal-template.test.ts: extract amounts to typed locals so single-value assertions no longer compare against unknown - category-template-context.test.ts: replace `as unknown as DbCategory` double-cast with a fully-typed object using `satisfies DbCategory` (the previous mock had `is_income: true` which doesn't match the `1 | 0` shape the cast was hiding) - api/tsconfig.build.json: broaden test exclude pattern to `**/*.test.ts` Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * [AI] Drop tsconfig.build.json for loot-core and api The build-config indirection was incomplete protection: typecheck (`tsgo -b` against the main tsconfig, which now includes test files) already emits `*.test.d.ts` into `@types/`, and the build step does not clean before re-emitting. The same is observable in crdt's `dist/`, which currently contains test declarations on disk. What actually keeps test declarations out of the npm tarball is the `files` field in package.json — and loot-core already uses that mechanism for source files (`\!src/**/*.test.ts`). Extending the same pattern to `@types/` is more direct than maintaining a duplicate tsconfig that doesn't reliably do its job. - Delete loot-core/tsconfig.build.json; revert build to `tsgo -b`; add `\!@types/**/*.test.d.ts*`, `\!@types/**/__tests__/**`, `\!@types/**/__mocks__/**` to `files`. - Delete api/tsconfig.build.json; revert build to `vite build && tsgo --emitDeclarationOnly`; add `\!@types/**/*.test.d.ts*` to `files`. Verified: `yarn pack --dry-run` excludes all test declarations from both packages while production declarations still pack (428 .d.ts files for loot-core, methods.d.ts for api). Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * first pass at implementation * finished implementing what I feel would be a good user experience * padding update * added ability to use tab to select * release notes * updated release notes * auto highlights first entry * removed debug info * linting formatting * updated behavior with tags in the middle of stuff * minor improvements to ux * extracted TagAutocomplete functionality into its own file * rewrote TagAutocomplete using react-aria-components from scratch * linting * restored old autocomplete since I'm no longer using it * linting * capped results at 10 * bugfix * used tag css hook instead of notes tag formatter * added mobile support * fixed bug where inserting a tag at the end of the note wouldn't fire onChange handler * fixed bug where note would hover even though field was not focused * fixed bug with currentWord detection * some more minor UI bugs with the mobile UI * removed log statement * added aria-label * [autofix.ci] apply automated fixes * name to Input * updatedt ests * fixed tests * whitespace adjustment * removed debug from test * added tests and made a few fixes * tried to fix vrt * some new hooks to use * removed log statement * removed input from useCursorPosition * input ref value hook now triggers on mount * add extra padding * hide browser autocomplete when our popup is shown to avoid doubles * useFilteredTags hook and adjustments to mobile tag UI * switched from opacity to height transitioning * sorted filtered tags by startsWith first * updated highlighting logic for mouseover * [autofix.ci] apply automated fixes * fix tag ordering * button type * [autofix.ci] apply automated fixes * release note update * release note to trigger ci * reverted db change * Revert "reverted db change" This reverts commit 24ce5450e5e4261e77fe5056620c240da22869a3. * can now filter by tags without hashes * extracted a method and added a new hasAnyTags rule * added hasAnyTag, still need to figure out why tests are failing * fixed unit tests * release notes * fixed based on coderabbit * tag.toLowerCase() * variable scope fix * fixed some focus-related bugs * allow creating tags in the dropdown for desktop * fixed focus issues with useCursorPosition * added Create Tag functionality to mobile * tests and added some length clipping as qol * can now use enter to submit new tag properly * centralized overflow CSS for tags * centered the text horizontally * added textnowrap * release notes * linting * fixed issue with async keydown handler * specified only to use new tag css for the autocomplete stuff * forgot to add new option to tag table * removed Trans * started working on multiselect * multiselect is now functional * finished multiAutocomplete implementation * [autofix.ci] apply automated fixes * removed double input * added multi autocomplete to rule editor * adjusted padding for TagMultiAutocomplete * adjusted hover cursor * release notes * fixed rule conditions * added tag styling to filter multiselect * spacing adjustment * release notes for retriggering build * added hidden migration * added hidden to models * added tags-hide-all and tags-unhide-all actions * added hide and unhide tags actions * added SelectedTagsButton * added UI elements for hiding/showing tags * release notes * removed delete from ManageTags * added icons to menu * coderabbit * coderabbit * updated mutations for translations * coderabbit * removed not null requirement * attempted to fix tests? * removed duplicate filterTags * [autofix.ci] apply automated fixes * updated release notes * release note update * updated migration timestamp * moved tags menu button --------- Co-authored-by: github-actions[bot] <[email protected]> Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]> Co-authored-by: Alec Bakholdin <alecbakholdin.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * automation UI: improve scaling (#8080) * improve scaling on high zoom levels * note * automation UI: rework balance cap and fix error when clearing fields (#8082) * fix safeNumber error * rework balance cap UI to be more readable * note * add explanation to balance cap * Bump react-router in the npm_and_yarn group across 1 directory (#8072) Bumps the npm_and_yarn group with 1 update in the / directory: [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router). Updates `react-router` from 7.14.2 to 7.15.0 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router) --- updated-dependencies: - dependency-name: react-router dependency-version: 7.15.0 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * [AI] feat(currencies): add currency-precision-aware helpers (#8064) * [AI] feat(currencies): add getDecimalPlaces/getCurrencyPrecisionMultiplier helpers, encodeAmount, currency-aware integerToCurrencyWithDecimal * Fix typo in release note * Use it.each in unit tests * Rename encodeAmount and replace its body; remove getCurrencyPrecisionMultiplier * [AI] Remove AI-generated release notes workflow and support custom filenames (#7963) * [AI] Relax release-notes filename convention Allow descriptive filenames (e.g. add-payee-autocomplete.md) for upcoming release notes instead of requiring {PR_NUMBER}.md. The PR number was only used to build the [#1234](.../pull/1234) link in the generated changelog. The generation script now resolves the PR per file by finding the commit that added it (git log --diff-filter=A --follow) and querying GitHub's commits/{sha}/pulls endpoint. Numeric filenames remain valid via a fast path. Also retires the CodeRabbit/OpenAI-triggered auto-creator workflow, which existed to guess summaries and stamp the PR-numbered filename; neither is needed once contributors can pick a slug up front. * Add release notes for PR #7963 * [AI] Use execFile to look up release-note add-commits resolvePrNumber() interpolated a path from fs.readdir into a shell- evaluated `git log` command. Switch to execFile with an argv array so filenames containing shell metacharacters can't break out of the intended command. * [AI] Drop duplicate release note added by the to-be-removed auto-creator The CodeRabbit-triggered workflow ran one last time from master before this PR removes it, and committed upcoming-release-notes/7963.md duplicating the existing relax-release-notes-filenames.md entry. Keep the slug-named note since it exercises the new flexible-filename code introduced in this PR. * [AI] Don't fail release-notes generation on transient API errors fetchPrForCommit() handled non-OK HTTP responses but let fetch() and res.json() exceptions propagate, so a single network blip or malformed response would abort the whole release-notes generation. Wrap them in a try/catch that logs and returns null, matching the pattern already used in resolvePrNumber for execFile errors. * [AI] Address CodeRabbit full-review nits - bin/release-note-generator.ts: tighten slug regex to reject trailing and consecutive dashes (matching slugify output), and make slugify fall back to "untitled" so an all-non-alphanumeric input can't produce a hidden ".md" filename. - packages/ci-actions/bin/release-notes-check.mjs: switch to execFile for git fetch/diff, matching release-notes-generate.mjs and removing shell interpolation of BASE_REF. - packages/ci-actions/bin/release-notes-generate.mjs: explicitly check GITHUB_REPOSITORY before splitting, consistent with the other env var guards a few lines below. - upcoming-release-notes/relax-release-notes-filenames.md: fix author casing (matiss -> MatissJanis) so changelog attribution is correct. * [AI] Reject empty release-note bodies content.trim().split('\n').length === 1 is true for the empty string (''.split('\n') returns [''] of length 1), so blank notes slipped past the single-line check. Reject empty trimmed content explicitly. * [AI] Resolve PR numbers from commit subjects instead of GitHub's API parseReleaseNotes was doing one GitHub API round-trip per non-numeric release-note file. That scales badly for release generation, and the docs site's generate-upcoming-release-notes.mjs runs on every docs build — so contributors were hitting the GitHub API (or failing 401 without a token) every time they previewed docs locally. actualbudget squash-merges every PR through the GitHub UI, which appends "(#NNNN)" to the resulting commit subject. So: git log -1 --format=%s -- <path> plus a /\(#(\d+)\)\s*$/ match recovers the PR number without touching the network, and works offline / without a GITHUB_TOKEN. Side effect: switched from "first commit that added this file" to "most recent commit touching this file", which is what we actually want — when a file is renamed (e.g. 7907.md -> 7954.md when a wrong PR number is corrected), the changelog should point at the rename PR, not the original add. The SHA->PR cache and fetchPrForCommit go away; no longer needed. If a file's subject doesn't match (direct push to master, manually rewritten subject), the entry still emits without a PR-link prefix — same graceful degradation as before. * [AI] Pin PR-number lookup to each note's add commit resolvePrNumber was using git log -1 with no diff filter, returning the latest commit that touched the file. That's fine until someone edits an existing release note in a follow-up PR (typo fix, author correction) — at which point the changelog entry would suddenly point at the wrong PR. Add --diff-filter=A so the lookup pins to the commit that originally added the path. Empirically verified against this repo: renames keep working (git records a rename as A at the new path when --follow isn't used), and the edit case now correctly returns the original add commit instead of the most recent touch. --------- Co-authored-by: Claude <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [AI] Add GitHub workflow to block PRs with "do not merge" label (#8090) * [AI] Add CI job that fails when 'do not merge' label is set * [AI] Rename do not merge check job to "Block PRs with do not merge label" * [AI] Rename do not merge workflow to "Block PRs with do not merge label" * [AI] Add release notes for do not merge CI check * Update 8090.md --------- Co-authored-by: Claude <[email protected]> * [AI] Persist bank sync status in the accounts table (#8017) * [AI] Persist bank sync status in the accounts table Extracts the persisted bank-sync-status half of #7782 (by @jcam): adds a bank_sync_status column to the accounts table, writes the status (pending/ok/failed/reauth-required/attention-required) during native bank syncs, and reads the persisted value in the UI (sidebar, account header, mobile account pages, and the sync banner) instead of ephemeral Redux state. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Add release note for persisted bank sync status https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Persist only durable failure states, keep pending ephemeral Addresses review feedback: a transient 'pending' write could get stuck in the DB (and propagated via CRDT) if the app closed mid-sync. The DB now only stores durable result states (ok / failed / reauth-required / attention- required); pending stays in ephemeral Redux state (account.accountsSyncing) as before. The UI reads only the persisted failure state via isAccountFailedSync, and the BankSyncStatus banner reverts to the ephemeral in-flight count. Also extracts a persistBankSyncError helper and inlines a redundant wrapper. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Un-export AccountSyncSidebar, refine release note - AccountSyncSidebar is internal again; drop the export-only-for-test and its test (the failure logic is already covered by syncStatus.test.ts). - Credit MatissJanis in the release note and make it user-centric. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Publish account changes in bank-sync sync-events handleSyncResponse writes accounts.last_sync and accounts.bank_sync_status, but the sync-events following it only declared tables: ['transactions'], so clients only refetch useAccounts when the event includes 'accounts'. Add 'accounts' to the six emissions that follow handleSyncResponse (the four link flows and the two batch-sync finals) so the persisted account changes are published everywhere, not just on the triggering client. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD * [AI] Re-timestamp bank_sync_status migration after master A newer migration (add_tags_hidden) landed on master, so bump the bank_sync_status migration's timestamp to remain the latest and satisfy the migration-ordering check. https://claude.ai/code/session_014MXn6Qi8skvFL9kXw7ctFD --------- Co-authored-by: Claude <[email protected]> * Remove environment from release notes workflow (#8091) * Remove environment from release notes workflow Removed the environment specification from the release notes workflow. * Update release-notes CI job configuration Removed the unnecessary 'environment' from the release-notes CI job. * [AI] Enable "do not merge" check on merge queue events (#8092) * [AI] Run do-not-merge check on merge_group events The block-do-not-merge workflow only triggered on pull_request events, so it never ran in the merge queue and could not be made a required check. Adding the merge_group trigger lets the job run and pass in the queue context (where pull_request labels are absent), allowing it to be required. * [AI] Add release notes for merge queue do-not-merge fix --------- Co-authored-by: Claude <[email protected]> * Make payee & categories searching to be case-insentive (#8079) * make payee & categories searching to be case-insentive * add release notes * [autofix.ci] apply automated fixes * Update VRT screenshots Auto-generated by VRT workflow PR: #8079 * update release-note * [autofix.ci] apply automated fixes * fix release-note format --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Add files via upload (#8096) * [AI] Fix incorrect schedule value when saving full amount (#8085) If one has a yearly schedule and the budget template uses "Cover each occurence when it occurs", it still showed a value for the yearly schedule even though it's not the month where the schedule occurs. Co-authored-by: Gemini <[email protected]> * feat: add SharedArrayBuffer warning indicator in title bar (#7922) * feat: add SharedArrayBuffer warning indicator in title bar * improve styling * add warning label * fix typo * review comments fixed * use link instead of button * fix tooltip styles * add hover effect --------- Co-authored-by: Awais Saeed <[email protected]> * [AI] Remove experimental status from Actual CLI (#8102) * [AI] Move actual-cli out of experimental status * [AI] Rename CLI release note to a feature slug --------- Co-authored-by: Claude <[email protected]> * add warning when schedule/save by automation priorities don't match (#8088) * add warning when schedle/save by automation priorities don't match * note * italicise * feat(reports): scoped ErrorBoundaries for individual report routes (#7658) * feat(reports): scoped ErrorBoundaries for individual report routes (#7391) Wrap each route in ReportRouter for NetWorth, CashFlow, Spending, etc. in ErrorBoundary with FeatureErrorFallback. Matches the pattern used for /rules routes in FinancesApp.tsx so a render error in a single report no longer takes down the whole app. * chore: rename release note to PR number * refactor(reports): extract withReportBoundary helper to remove route boilerplate Each report route was wrapping its element in the same ErrorBoundary block with FeatureErrorFallback and resetKeys={[location.pathname]}. Pull that into a small withReportBoundary(element) helper inside ReportRouter so each route is one line again. Behavior is unchanged. The ErrorBoundary, FallbackComponent, and resetKeys are identical to before; the helper just closes over location.pathname. Addresses review feedback from @joel-jeremy and the CodeRabbit nitpick on the same file (a custom Route component is not viable since react-router v6's <Routes> requires literal <Route> children, but a helper function gives the same boilerplate reduction). * refactor(reports): hoist withReportBoundary to ReportBoundary component Move the per-route error-boundary helper out of ReportRouter as a module-scoped component. ReportBoundary calls useLocation() internally so each call site stays clean. Addresses review feedback. --------- Co-authored-by: github-actions[bot] <[email protected]> Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Add configurable average ranges to Monthly Spending report (#7920) * Add configurable average ranges to Monthly Spending report * Delete upcoming-release-notes/temp.md * Update packages/desktop-client/src/components/reports/spendingAverageRange.test.ts Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Fix spending average range test import * Update VRT screenshots Auto-generated by VRT workflow PR: #7920 --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: youngcw <[email protected]> * [AI] Fix custom report transfer drilldown filters (#8001) Co-authored-by: youngcw <[email protected]> * Make tag search case-insensitive (#8093) * makes tags case insensitive * release notes --------- Co-authored-by: Alec Bakholdin <alecbakholdin.com> * docs: add Hostim to Additional Installation Options (#8066) * docs: add Hostim to community install options Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * docs: add release note for #8066 Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * docs: drop release note (not required for docs-only change) --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> Co-authored-by: youngcw <[email protected]> * [AI] Add SSRF protection to SimpleFIN bank sync integration (#8012) * [AI] Add SSRF protection to SimpleFIN bank sync integration The SimpleFIN integration made server-side HTTP requests to user-controlled URLs (the base64-encoded claim token and the resulting access-key base URL) without any validation, unlike the CORS proxy which blocks private IPs via ipaddr.js. Add a shared assertUrlAllowed() helper that rejects non-http(s) URLs and blocks requests to private, loopback, link-local, unique-local, reserved, broadcast and unspecified addresses. Hostnames are resolved via DNS so names pointing at internal addresses are blocked too, not just literal IPs. Apply it before both outbound requests in getAccessKey() and getAccounts(). * [AI] Unify CORS proxy private-IP check with shared SSRF helper The CORS proxy had its own inline ipaddr.js private-IP check that duplicated the logic in the SimpleFIN SSRF helper. Export isBlockedIp() from util/ssrf and reuse it in app-cors-proxy, removing the duplicate. This also widens the CORS proxy's coverage to the reserved and broadcast ranges and normalizes IPv4-mapped IPv6 addresses, matching the SimpleFIN helper. The cors-proxy tests now exercise the real ipaddr.js against real private IPs instead of mocking it. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Rename SimpleFIN SSRF release note to match PR number Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * Implement SSRF protection for SimpleFIN bank sync Requests to private, loopback, link-local, and other internal addresses are now blocked. * [AI] Allow self-hosted private SimpleFIN servers by default The SSRF protection blocked all private/loopback addresses, which broke self-hosters running their own SimpleFIN bridge on a LAN or VPN IP with no way to opt back in. Split the blocked ranges into two tiers: link-local (cloud metadata), reserved, broadcast and unspecified stay blocked unconditionally, while private/loopback/unique-local are blocked by default but can be permitted per-caller via { allowPrivateNetwork: true }. SimpleFIN opts in, so self-hosting works out of the box with no env var, while the worst-case cloud-metadata credential-theft vector remains closed. The CORS proxy keeps the strict default. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Re-validate SSRF rules on each SimpleFIN redirect hop getAccounts used fetch with redirect: 'follow', so a 3xx response from the validated SimpleFIN URL could redirect to a blocked internal address after only the initial URL had been checked. Follow redirects manually instead, calling assertUrlAllowed on every hop before fetching, capping at 5 redirects, and dropping Authorization on cross-origin hops so the bridge credentials cannot leak to a redirect target. getAccessKey uses https.request, which does not auto-follow redirects, so it is unaffected. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> --------- Co-authored-by: Claude <[email protected]> * [AI] Skip unimportable Enable Banking transactions instead of failing the whole sync (#8086) * [AI] Skip unimportable Enable Banking transactions instead of failing the whole sync Enable Banking bank-sync aborts the whole account import with a client-side SQLITE_ERROR when a fetched transaction cannot be inserted — most commonly a pending transaction with no booking/value/transaction date (normalized to date ''), or a non-numeric amount. Add an isImportableTransaction helper and skip such records in the /transactions handler (logging the count) so the rest of the account imports. Dated pending transactions are unaffected. * [AI] Add release note for #8086 * [AI] Reject empty Enable Banking transaction amounts Number('') is 0 (finite), so an empty/whitespace amount slipped through isImportableTransaction as a zero transaction. Trim and reject empty amounts explicitly, with a test. Addresses PR review feedback. * Update packages/sync-server/src/app-enablebanking/services/enablebanking-service.ts Co-authored-by: Matiss Janis Aboltins <[email protected]> * Update packages/sync-server/src/app-enablebanking/app-enablebanking.ts Co-authored-by: Matiss Janis Aboltins <[email protected]> * [AI] Remove now-unused skippedCount counter The summary log that read it was removed when accepting the review suggestion; drop the dangling write-only counter so the loop matches the per-transaction skip log that remains. --------- Co-authored-by: Matiss Janis Aboltins <[email protected]> * [AI] Disable ESLint in CodeRabbit configuration (#8110) * [AI] Disable ESLint in CodeRabbit config * [AI] Add release notes for CodeRabbit ESLint change * [AI] Rename release notes to match PR number 8110 * [AI] Rename release notes file to a slug --------- Co-authored-by: Claude <[email protected]> * Feature: Add Akahu New Zealand bank sync (#6041) * add akahu integration for nz banks * akahu fix bank name being set to account name * rename apiToken and fix reset pointing to the wrong function * fix apitoken wording in akahu init modal * add upcoming-release-notes * fix lint issues * fix lint issues * add loan account type to starting balance inversion * fix initial sync balance * initially select 365 days of transactions on first sync for akahu sync * add SyncServerAkahuAccount to onSetLinkedAccount * set transaction currency to account currency * remove unnecessary code * handle TFR TO/FROM payees and account for loan account type in transactions * [autofix.ci] apply automated fixes * rename Error to ErrorAlert and fix intial sync start date * extract note from description for TFR TO/FROM transactions * fix normalizeNotes not referencing the transaction * refactor app-akahu code * [autofix.ci] apply automated fixes * Add Akahu to ExternalAccount type * Update yarn.lock * update yarn.lock * Remove unused error var in catch block * [autofix.ci] apply automated fixes * require authentication for akahu endpoint * fix lint issue in mutations.ts * fix up import paths * fix lint issues * reorder form fields * remove unnecessary handling for debt accounts * lint fixes * Put Akahu bank sync under feature flag * remove incorrect feedback link * [autofix.ci] apply automated fixes * Add feedback link for feature toggle * use uuidv4 * prevent fetch if feature not enabled * change app-akahu to ts and tidy up * fix typecheck errors * [autofix.ci] apply automated fixes * fix browser client build issues * [autofix.ci] apply automated fixes * update akahu npm package to latest version * use amountToInteger for balance reducer * add additional details to transactions * change initial sync start date logic * add akahu fields to mappable fields in desktop-client * [autofix.ci] apply automated fixes * getDate use formatISO to get the timezone adjusted date * remove duplicate payeeName --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> * automation UI: add mobile support 📱 (#8099) * generalise out to hooks * add mobile modal * wire up mobile * tidy up field styling on mobile * [AI] add mobile automations e2e test Covers opening the editor from the mobile category menu, the drill-down list/editor navigation, touch-sized fields, and that Cancel dismisses it. Co-Authored-By: Claude Opus 4.8 <[email protected]> * note * Update VRT screenshots Auto-generated by VRT workflow PR: #8099 * fix date picker on schedule page * fix conflict * fix cramped space in save by automation --------- Co-authored-by: Claude Opus 4.8 <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * [Docs] Starting at the top, Introduction & Vision (#8083) * Enhance introduction and navigation details in docs Revised wording for clarity and improved navigation instructions in the documentation. * Update vision.md for clarity and formatting Refine language for clarity and consistency, and update formatting for better readability. * Improve formatting of third-party use section Reformatted the third-party use section for clarity. * Revise documentation introduction and navigation details Updated the introduction and navigation instructions for clarity and conciseness. * Revise documentation overview and navigation details Updated documentation for clarity and navigation instructions. * Refine Local-first explanation in vision.md Removed redundant text in the Local-first section. * [autofix.ci] apply automated fixes * Revise contribution guidelines in documentation Updated links to contributing guides and documentation readme. * Revise headings and improve hyphenation in vision.md Updated headings and corrected hyphenation in vision.md. * [autofix.ci] apply automated fixes * Fix wording in contribution guidelines section Corrected the wording from 'documentation standard' to 'documentation standards' for clarity. --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matiss Janis Aboltins <[email protected]> * [AI] Fix bank sync deadlock from nested mutator (#8111) * [AI] Fix bank sync deadlock from nested mutator PR #8017 wrapped the accounts-bank-sync and simplefin-batch-sync handlers in mutator(). runHandler runs mutators via runMutator, which is sequential() — only one mutator may run at a time and re-entrant calls are queued. These handlers call syncAccount -> reconcileTransactions, which already invokes runMutator internally. The inner runMutator gets queued behind the still-running outer one while the outer awaits it, deadlocking forever. The bank sync send() never resolves, so the mobile spinner spins indefinitely. Remove the mutator() wrapping (restoring pre-#8017 registration). The DB writes for bank_sync_status/last_sync already ran outside a mutator before * [AI] Add regression tests for bank sync mutator deadlock Guards against re-wrapping the accounts-bank-sync / simplefin-batch-sync handlers in mutator(), which deadlocks because the sync internally calls runMutator (reconcileTransactions) and runMutator is sequential. - An invariant test asserts neither handler is a mutating method. - A behavioral test drives accounts-bank-sync through runHandler with a syncAccount mock that performs its own runMutator, and fails via a timeout if the nested mutators deadlock. * [AI] Simplify deadlock regression test Collapse the two-step Promise.race into a single race result and clear the timeout timer on the success path so it doesn't linger after the test. * [AI] Remove explanatory comments from deadlock regression test * [AI] Add release note for bank sync deadlock fix * Update packages/loot-core/src/server/accounts/app-bank-sync.test.ts Co-authored-by: Matt Fiddaman <[email protected]> * Update packages/loot-core/src/server/accounts/app-bank-sync.test.ts Co-authored-by: Matt Fiddaman <[email protected]> --------- Co-authored-by: Claude <[email protected]> Co-authored-by: Matt Fiddaman <[email protected]> * [AI] Fix desktop settings resetting after an interrupted update (#8101) * [AI] Fix desktop settings resetting after an interrupted update Desktop global prefs (language, theme, etc.) live in a single global-store.json that was written non-atomically and silently reset to {} whenever it failed to parse. An app update's forced quit can truncate the file mid-write, so the next launch wiped every global pref - the language reverted to "System default" (the OS language). - Write the store via a unique temp file + atomic rename so it is never left half-written. - Serialize writes so a slower older write can't land after and clobber a newer one. - Back up an unparseable store to .corrupt and log loudly instead of silently discarding the user's preferences. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Reject non-object global-store contents during load JSON.parse could return a non-object (null, an array, a primitive) for parseable-but-wrong-shaped contents, which would then break store[key] access. Validate the parsed value is a plain object and route anything else through the existing back-up-and-default recovery path. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * :electron: Removed new shared array buffer warning on Electron (#8118) * removed shared array buffer warning one electron * release notes * cleanup a bit * Enhance translation contribution guidelines in i18n.md (#8113) * Enhance translation contribution guidelines in i18n.md Updated i18n.md to include new guidelines for contributing translations, account requirements, and voting on suggestions. * Update i18n.md * [AI] update contributor guidelines for AI usage (#8135) * [AI] Surface anti-slop and self-review expectations at PR time Drive-by, LLM-generated PRs (often many at once from one author) burn maintainer review time. The repo's AI usage policy already covers this, but contributors never see it in the PR flow. - Strengthen the fork-PR welcome comment to ask for a human self-review confirmation, a plain-language testing note, and AI disclosure, plus a note discouraging opening many PRs at once. - Add a "Quality Over Quantity" section to the AI usage policy naming the volume pattern and its consequences. - Add an AI-disclosure prompt and tighten the self-review item in the PR template. No mechanical CI gates on PR body content: those are trivially satisfied by the same tools that generate the slop, so the change relies on human accountability and a linkable policy instead. * [AI] Point welcome comment at the PR template instead of inline asks Replace the three "reply on this PR with" bullets with a single checklist item asking contributors to use the PR template and fill in its checkboxes, keeping the welcome comment short. * [AI] Add AI disclosure checklist item to fork PR welcome comment --------- Co-authored-by: Claude <[email protected]> * [AI] Fix CLI server version without open budget (#8117) * [AI] fix cli server version without open budget * Remove redundant expectation in get-server-version test Remove redundant expectation for get-server-version handler call. --------- Co-authored-by: Matiss Janis Aboltins <[email protected]> * [AI] Skip posted schedule occurrences in balance forecast (#8029) * [AI] Extract schedule occurrence match start date helper Centralize the lower-bound rules for matching posted transactions to schedule dates and reuse them in getHasTransactionsQuery, including the correct 2-day lookback for recurring schedules stored with op is. * [AI] Add schedule occurrence posted matching helpers Add isScheduleOccurrencePosted with the match-start logic built in and indexPostedScheduleTransactions for efficient per-schedule lookups. * [AI] Skip posted schedule occurrences in balance forecast Skip synthetic schedule occurrences when a posted transaction already covers that date, using indexed per-schedule lookups in the forecast path. * [AI] Add release notes for balance forecast schedule dedup fix * [AI] Treat op is schedule dates as exact match start Restore master semantics: recurring schedules with op is use exact occurrence matching, not a 2-day lookback. Remove conflicting tests. * [AI] Add daily recurring forecast dedup regression test Prove daily schedules with op is do not double-count when posted on the due date, while subsequent occurrences are still forecast. * [AI] Move browser web-worker logic into loot-core (#8143) * [AI] Move browser web-worker logic into loot-core Relocate the browser Web Worker bootstrap (WorkerBridge + startBrowserBackend) and the multi-tab SharedWorker coordinator from desktop-client into loot-core so they can be reused (e.g. by the api package in a browser). Behavior is preserved as faithfully as possible. The two Vite worker entry targets stay in desktop-client (the browser-server.js classic worker and the ?sharedworker entry); the ?sharedworker entry now imports the coordinator from loot-core. console.* calls in the moved code route through loot-core's logger, except the SharedWorker console-forwarding mechanism, which must keep the real console. absurd-sql's initBackend is imported directly (loot-core already depends on absurd-sql); the desktop-client dependency was dropped. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Rename release note to match PR number 8143 * Update release notes for Web Worker migration Removed mention of reuse by the API package in the release notes. * [AI] Drop move-related header comments per review Remove the "moved from desktop-client" header comments that only made sense in the context of this PR. worker-bridge.ts and start.ts had no header comment in the original source, so they're removed entirely; coordinator.ts's header is restored to its original wording. --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * Refresh akahu account if stale (#8115) * Refresh akahu account if stale * Update upcoming-release-notes/akahu-refresh.md * wait for the refresh to complete * check account is defined * use local variable * move into helper * increase poll delay * bump refresh interval to 1 hour * ensure only one account refresh is running at a time * [AI] Drop ACTIONS_UPDATE_TOKEN from release workflows (#8142) * [AI] Drop ACTIONS_UPDATE_TOKEN from release workflows Replace the implicit push-triggers-workflow link (which relied on the ACTIONS_UPDATE_TOKEN PAT) with an explicit workflow_run chain from "Cut release branch" to "Release notes", falling back to the built-in GITHUB_TOKEN. The PAT stays in vrt-update-apply.yml, which genuinely needs it to push to contributor forks and re-trigger their PR CI. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Add release note for ACTIONS_UPDATE_TOKEN removal Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * Update 8142.md --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * [AI] Consolidate agent tooling and simplify developer guidance (#8089) * [AI] Replace mechanical agent rules with shared agent hooks + nano-staged Move the mechanical "remember to run X" rules out of AGENTS.md and the agent guidance docs into deterministic, cross-agent hooks, and migrate the pre-commit runner from lint-staged to nano-staged. - Add shared hook scripts in scripts/agent-hooks/ (git-guard, format-edited-file, no-strict-ignore-new-file, prefer-one-component, check-on-stop, common helpers) wired for Claude (.claude/settings.json), Codex (.codex/config.toml), and Cursor (.cursor/hooks.json + adapters). - Enforce "avoid enum" via a new actual/no-enum lint rule, grandfathering the two existing declarations in .oxlintrc.json overrides. - Migrate lint-staged -> nano-staged (.nano-staged.json, .husky/pre-commit, package.json). - Trim AGENTS.md, .github/agents/pr-and-commit-rules.md, the Cursor rule, and the committing skill down to the rules that aren't auto-enforced. - Add release note 8089.md. * [AI] Align PR-title wording in AGENTS.md with canonical rules * [AI] Fix check-on-stop hook on bash 3.2 and TSV column collapse The Stop hook silently no-op'd in two ways: - `declare -A` isn't supported on stock macOS bash 3.2, and the slash/hyphen path subscript aborted under `set -u`. Dedupe via a space-padded string match instead. - jq emitted an empty middle TSV field for a package with test but no typecheck; tab is IFS-whitespace so `read` collapsed it and shifted the columns (eslint-plugin-actual then ran neither). Emit non-empty sentinels (-, yes/no) so no field can collapse. Co-Authored-By: Claude Opus 4.8 <[email protected]> --------- Co-authored-by: Claude <[email protected]> * [AI] docs(migration): expand nYNAB export with tabbed alternatives (#8155) Add CLI tool (ynab-export), YNAB API Documentation UI, and cURL as fallback export methods for when the third-party web exporter is unavailable. Converts nynab.md to MDX to support Docusaurus Tabs. Six new screenshots added for the API Documentation UI method. * Add Enable Banking PSU type selection (#8028) * Add Enable Banking PSU type selection * [autofix.ci] apply automated fixes * Add release note for Enable Banking PSU type selection --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Matt Fiddaman <[email protected]> * [AI] fix: translate transfer menu empty placeholder (#8161) * fix: translate transfer menu empty placeholder * docs: add release note for transfer placeholder fix * [AI] fix release note category * [AI] Add missing widget types to dashboard import validation (#8159) * [AI] Add missing widget types to dashboard import validation * [AI] Add test ensuring all widget types are covered by import validation * [AI] Add release notes for dashboard import widget type support * [AI] fix: clear split parent payee (#8005) Co-authored-by: Matiss Janis Aboltins <[email protected]> * Fix Sankey Budgeted view, when an amount is left to budget. (#8169) * Fix Budget view, when an amount is left to budget. * Add translation to To budget-node * docs: fix docs build & broken anchors, migrate to consistent link format (#8173) * fix broken anchors * enable build fail on broken anchors * move to relative links * Update check-spelling metadata * update style guide to match * coderabbit * [AI] docs: fix broken blog links and add enforce-doc-links remark plugin (#8180) * [AI] docs: fix broken blog links and add enforce-doc-links remark plugin - Fix three docs/ pages that linked to blog posts using URL slugs instead of file paths, with an extra ../ level in the relative path - Add src/remark/enforce-doc-links.js: remark plugin that enforces link hygiene in docs/ and blog/ at build time (no absolute internal links, .md extension required, slug-style links caught via frontmatter cache) - Upgrade onBrokenMarkdownLinks from 'warn' to 'throw' so broken .md file-path links fail the build rather than being silently ignored * [autofix.ci] apply automated fixes * [AI] docs: add vfile to spell-check allowlist * [AI] docs: fix build failures from cross-plugin and absolute links - Revert docs→blog links to URL-slug style (Docusaurus cannot resolve .md file paths across content plugins — blog is a separate plugin from docs) - Fix absolute /docs/... links in two blog posts to relative URL form - Fix generate-upcoming-release-notes.mjs hardcoded /docs/releases absolute URLs to relative ./releases.md paths - Update enforce-doc-links plugin: exempt docs→blog URL-slug links from Rule 3 (cross-plugin constraint means slug URLs are the req…
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Fix #11923
webpack v5.106 kind of shipped a breaking change that affects Docusaurus v3 users when they upgrade Webpack, due to an older version of webpackbar we use.
Since they'd rather keep their behavioral change, and we can easily upgrade webpackbar to the latest major version, let's do the upgrade on our side so that Docusaurus v3 users do not encounter the bug anymore.
This can still affect Docusaurus users <= v3.10.0, but will be fixed in v3.10.1
Test Plan
See individual commits: