Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
212 commits
Select commit Hold shift + click to select a range
1419766
Merge pull request #1 from nehraa/copilot/improve-project-features
nehraa Mar 14, 2026
d7b2847
Initial plan
Copilot Mar 14, 2026
6be13ee
Initial plan
Copilot Mar 14, 2026
96469e8
Initial plan
Copilot Mar 14, 2026
eab2935
Initial plan
Copilot Mar 14, 2026
ced68ee
feat: implement Time-Travel Branching for Blueprint Graphs
Copilot Mar 14, 2026
c416e0b
feat: Ghost Nodes — Predictive Architecture Suggestions in Visual Age…
Copilot Mar 14, 2026
d098945
feat: heatmap observability dashboard with live polling and trace vis…
Copilot Mar 14, 2026
ecdc89e
feat: add MCP client integration for node superpowers
Copilot Mar 14, 2026
d1b47fd
refactor: move MCP schemas before blueprintNodeSchema to remove z.lazy()
Copilot Mar 14, 2026
b1d79e4
test: add workbench test for branch panel UI, fix HTML entities
Copilot Mar 14, 2026
3a899d1
Potential fix for pull request finding
nehraa Mar 14, 2026
34fc507
Potential fix for pull request finding
nehraa Mar 14, 2026
ef788c7
Potential fix for pull request finding
nehraa Mar 14, 2026
14cf0b7
Potential fix for pull request finding
nehraa Mar 14, 2026
63c13f7
Potential fix for pull request finding
nehraa Mar 14, 2026
59d8f92
Merge pull request #14 from nehraa/copilot/add-heatmap-observability-…
nehraa Mar 14, 2026
8fe6d42
Potential fix for pull request finding
nehraa Mar 14, 2026
9282f33
Potential fix for pull request finding
nehraa Mar 14, 2026
a469174
Potential fix for pull request finding
nehraa Mar 14, 2026
cc04ce2
Potential fix for pull request finding
nehraa Mar 14, 2026
546a170
Potential fix for pull request finding
nehraa Mar 14, 2026
b0a3f6b
Potential fix for pull request finding
nehraa Mar 14, 2026
e6ddc6b
Potential fix for pull request finding
nehraa Mar 14, 2026
1934938
Potential fix for pull request finding
nehraa Mar 14, 2026
8cd1943
Potential fix for pull request finding
nehraa Mar 14, 2026
af8ce51
Potential fix for pull request finding
nehraa Mar 14, 2026
817fe2b
Potential fix for pull request finding
nehraa Mar 14, 2026
6a05251
Potential fix for pull request finding
nehraa Mar 14, 2026
511b4df
Potential fix for pull request finding
nehraa Mar 14, 2026
c7045f4
Potential fix for pull request finding
nehraa Mar 14, 2026
abc25e3
Potential fix for pull request finding
nehraa Mar 14, 2026
49846d8
Potential fix for pull request finding
nehraa Mar 14, 2026
b680d3b
Potential fix for pull request finding
nehraa Mar 14, 2026
9599c8f
Potential fix for pull request finding
nehraa Mar 14, 2026
abf3fd6
Potential fix for pull request finding
nehraa Mar 14, 2026
3b53391
Merge main into integrate-mcp-client-servers
nehraa Mar 14, 2026
1d1cf9b
Merge main into add-time-travel-branching
nehraa Mar 14, 2026
e47573d
Merge main into add-ghost-nodes-suggestions
nehraa Mar 14, 2026
3c209de
Merge pull request #13 from nehraa/copilot/integrate-mcp-client-servers
nehraa Mar 14, 2026
5ea2fc3
Merge latest main into add-time-travel-branching
nehraa Mar 14, 2026
fbbcb2f
Merge latest main into add-ghost-nodes-suggestions
nehraa Mar 14, 2026
8ca5a1a
Merge pull request #11 from nehraa/copilot/add-time-travel-branching
nehraa Mar 14, 2026
4609ee8
Merge latest main into add-ghost-nodes-suggestions
nehraa Mar 14, 2026
97e6492
Merge pull request #12 from nehraa/copilot/add-ghost-nodes-suggestions
nehraa Mar 14, 2026
3f2bfbb
Harden AI blueprint JSON parsing
nehraa Mar 14, 2026
fec5326
Redesign policy canvas graph view
nehraa Mar 14, 2026
0168067
Initial plan
Copilot Mar 14, 2026
4e0a769
feat: add VCR time-travel debugging with scrub bar replay
Copilot Mar 14, 2026
87de8fb
fix: use clearer step-forward icon in VCR transport controls
Copilot Mar 14, 2026
d3f82c7
Potential fix for pull request finding
nehraa Mar 14, 2026
decb911
Potential fix for pull request finding
nehraa Mar 14, 2026
53464cb
Potential fix for pull request finding
nehraa Mar 14, 2026
c023be2
Potential fix for pull request finding
nehraa Mar 14, 2026
915916f
Potential fix for pull request finding
nehraa Mar 14, 2026
dc83233
Potential fix for pull request finding
nehraa Mar 14, 2026
1722c4b
Merge pull request #15 from nehraa/copilot/nehraa-add-scrub-bar-ui
nehraa Mar 14, 2026
5a1ccf7
Initial plan
Copilot Mar 14, 2026
99b5bdf
feat: add Digital Twin real-time production mirroring
Copilot Mar 14, 2026
c06cb12
Potential fix for pull request finding
nehraa Mar 14, 2026
bf8c872
Potential fix for pull request finding
nehraa Mar 14, 2026
78e2256
Potential fix for pull request finding
nehraa Mar 14, 2026
ad75470
Potential fix for pull request finding
nehraa Mar 14, 2026
eee5ab4
Potential fix for pull request finding
nehraa Mar 14, 2026
ae492bc
Potential fix for pull request finding
nehraa Mar 14, 2026
4a42912
Potential fix for pull request finding
nehraa Mar 14, 2026
8b9656a
Potential fix for pull request finding
nehraa Mar 14, 2026
0bec23f
Merge pull request #16 from nehraa/copilot/digital-twin-real-time-mir…
nehraa Mar 14, 2026
e75762b
Initial plan
Copilot Mar 14, 2026
0682d73
Initial plan
Copilot Mar 14, 2026
58c1fff
Add Neural Auto-Refactoring: drift detection, healing API, shake anim…
Copilot Mar 14, 2026
7397e51
feat: Architectural Genetic Algorithms — multi-agent evolution of wor…
Copilot Mar 14, 2026
62d77e6
refactor: address code review feedback on genetic algorithms
Copilot Mar 14, 2026
5960d3f
Potential fix for pull request finding
nehraa Mar 15, 2026
efc1612
Potential fix for pull request finding
nehraa Mar 15, 2026
a9a1eed
Potential fix for pull request finding
nehraa Mar 15, 2026
c83af3c
Potential fix for pull request finding
nehraa Mar 15, 2026
440554c
Potential fix for pull request finding
nehraa Mar 15, 2026
d75c7d2
Potential fix for pull request finding
nehraa Mar 15, 2026
0f79e3d
Potential fix for pull request finding
nehraa Mar 15, 2026
a6da400
Potential fix for pull request finding
nehraa Mar 15, 2026
77cee7f
Potential fix for pull request finding
nehraa Mar 15, 2026
269645f
Potential fix for pull request finding
nehraa Mar 15, 2026
01883ad
Merge pull request #17 from nehraa/copilot/nehraa-architectural-genet…
nehraa Mar 15, 2026
edec6ad
Address review feedback: fix broken-edge nodeId, dedup key, shake ani…
Copilot Mar 15, 2026
62e0b34
Merge main into pr-18
nehraa Mar 15, 2026
022c626
Merge pull request #18 from nehraa/copilot/nehraa-neural-auto-refacto…
nehraa Mar 15, 2026
f098df8
refactor: split persistence layer into domain-specific stores
nehraa Mar 27, 2026
5af42c8
feat: enhance blueprint schema for execution tracking and artifacts
nehraa Mar 27, 2026
dec0497
feat: core infrastructure for runtime workspaces and test execution
nehraa Mar 27, 2026
7cd4fc5
feat: core execution engine overhaul with steps, artifacts, and test …
nehraa Mar 27, 2026
6a6e7a6
feat: api route updates for core blueprint execution and management
nehraa Mar 27, 2026
96447d7
feat: enhance api routes for observability, digital twin, and code as…
nehraa Mar 27, 2026
5ab5de9
feat: workbench UI enhancements and new showcase components
nehraa Mar 27, 2026
833b594
feat: library enhancements for codegen, digital twin, and graph refac…
nehraa Mar 27, 2026
3063b85
docs: project-wide documentation and configuration updates
nehraa Mar 27, 2026
3862cde
fix: update approval API route with latest persistence logic
nehraa Mar 27, 2026
0a30e22
🎨 Palette: Add ARIA labels to VCR playback buttons
google-labs-jules[bot] Mar 27, 2026
2968746
Merge pull request #20 from nehraa/palette-ux-vcr-a11y-17691744943390…
nehraa Mar 27, 2026
ec940bf
fix: address PR review comments for security, correctness, and perfor…
Claude Mar 27, 2026
c46f01b
Merge pull request #19 from nehraa/feat/blueprint-workbench-evolution
nehraa Mar 27, 2026
ddf34a4
feat: Integrate CodeRag for intelligent code retrieval
nehraa Apr 2, 2026
ab37d76
Fix CodeRag export indexing paths
nehraa Apr 2, 2026
10fbd89
Cat aniimations
nehraa Apr 2, 2026
ece89cc
feat: add file tabs and file tree explorer
nehraa Apr 2, 2026
f6146b4
chore: add claude-code and serena to gitignore
nehraa Apr 2, 2026
2dec8a9
feat: Add secure file I/O API routes for Monaco integration
nehraa Apr 3, 2026
eedbf0d
chore: initial plan tracking
Copilot Apr 3, 2026
e7dec70
fix: address all security review comments on file I/O API routes
Copilot Apr 3, 2026
6e04a21
fix: address all PR review comments - security, a11y, perf, tests, wi…
Copilot Apr 3, 2026
0dc4868
Merge pull request #22 from nehraa/feat/file-io-api-routes
nehraa Apr 3, 2026
2b98cd8
merge: resolve conflicts in files/get route
nehraa Apr 3, 2026
947d7ef
added integration plan
nehraa Apr 3, 2026
132b13d
Add production readiness analysis for 15 GitHub repos
nehraa Apr 3, 2026
2c796b0
Add all 15 GitHub repository clones with production readiness analysis
nehraa Apr 3, 2026
5b3fd1b
feat: P1-P3 IDE mode foundation, repo-scoped APIs, Monaco setup
nehraa Apr 3, 2026
9d3fb79
feat: P4 graph-to-editor navigation
nehraa Apr 3, 2026
e797f45
feat: P5 editor intelligence - repo-aware TypeScript
nehraa Apr 3, 2026
5e89422
feat: P6 workbench IDE mode integration
nehraa Apr 3, 2026
6bb6136
feat: P7 full CodeFlow feature parity in IDE mode
nehraa Apr 3, 2026
0d4ceb3
feat: P8 startup scripts + Playwright E2E tests
nehraa Apr 3, 2026
1c72d93
feat: Complete CodeFlow IDE Mode Implementation
nehraa Apr 4, 2026
831c8fd
Revert "Add production readiness analysis for 15 GitHub repos"
nehraa Apr 4, 2026
423b279
Add CodeQL analysis workflow
nehraa Apr 4, 2026
b2f71a7
Merge pull request #23 from nehraa/remove-analysis-commits
nehraa Apr 4, 2026
f704a79
fix(opencode): add specific API key patterns for all 11 providers
nehraa Apr 4, 2026
647432a
fix(opencode): mark provider as manually selected when user changes d…
nehraa Apr 4, 2026
56f1542
test(opencode): add comprehensive detection tests for all providers
nehraa Apr 4, 2026
8c97099
fix(opencode): remove duplicate closing brace in provider dropdown
nehraa Apr 4, 2026
a685ae5
feat(opencode): add model fetcher for API key validation and model di…
nehraa Apr 4, 2026
9ad3b83
feat(opencode): add API key validation UI component
nehraa Apr 4, 2026
12c9161
feat(opencode): integrate API key validator into settings component
nehraa Apr 4, 2026
c551f00
feat(opencode): export modelFetcher from module index
nehraa Apr 4, 2026
c44e827
test(opencode): add comprehensive tests for model fetcher
nehraa Apr 4, 2026
2197b1c
Merge pull request #24 from nehraa/remove-analysis-commits
nehraa Apr 4, 2026
a6d032b
chore(codeflow-core): add tree-sitter language grammar dependencies
nehraa Apr 6, 2026
c980ade
feat(codeflow-core): add tree-sitter loader and language queries
nehraa Apr 6, 2026
fb6f184
feat(codeflow-core): add analyzeRepo orchestrator with tree-sitter AS…
nehraa Apr 6, 2026
2863363
fix(codeflow-core): resolve all TypeScript compile errors in tree-sit…
nehraa Apr 6, 2026
cccc4a0
test(codeflow-core): add sample repo fixtures for all 6 languages
nehraa Apr 6, 2026
fde60c5
feat(codeflow-core): all 10 tests pass for multi-language analyzeRepo
nehraa Apr 6, 2026
ba9aad5
fix(codeflow-core): prevent duplicate extraction of class methods
nehraa Apr 6, 2026
964c6e8
fix(codeflow-core): match import paths to module nodes across extensions
nehraa Apr 6, 2026
59a51ed
chore(codeflow-core): rebuild dist with latest fixes
nehraa Apr 6, 2026
3126fda
test: verify pre-commit hook fires
nehraa Apr 6, 2026
8cbdcaa
chore: remove test hook verification file
nehraa Apr 6, 2026
85db892
fix(codeflow-core): address all PR review comments
Claude Apr 6, 2026
ecd27b4
fix(codeflow-core): address additional PR review findings
Claude Apr 6, 2026
bbf3538
Merge pull request #25 from nehraa/remove-analysis-commits
nehraa Apr 7, 2026
5beb6cb
updated the verison
nehraa Apr 7, 2026
8da01c6
chore: bump version to 1.0.0 and fix ghost-nodes test env leak
nehraa Apr 7, 2026
5104ffb
chore: add .qwen to gitignore, add source spans and call sites to ana…
nehraa Apr 7, 2026
0fb4545
probabrly last commit for this monorepo
nehraa Apr 21, 2026
e8a92e9
docs: add FEATURES.md with complete feature list
nehraa Apr 21, 2026
d8423c5
docs: add PACKAGE_DECOMPOSITION with full package plan
nehraa Apr 21, 2026
8037042
feat(codeflow-mcp): extract MCP package with test_tool and JSON-RPC s…
nehraa Apr 21, 2026
8978511
feat(codeflow-mcp): extract MCP package with test_tool and JSON-RPC s…
nehraa Apr 21, 2026
cad9b0c
feat(codeflow-mcp): add stdio and SSE transports for maximum MCP comp…
nehraa Apr 21, 2026
7b57d5a
test: add invoke/index.test.ts for MCP server protocol coverage
nehraa Apr 21, 2026
2434813
test: add tools/index.test.ts and cli.test.ts, reach 40 tests total
nehraa Apr 21, 2026
dba6ba5
test(codeflow-store): add comprehensive tests for all store modules
nehraa Apr 21, 2026
a050846
docs: fix PACKAGE_DECOMPOSITION.md per review feedback
Copilot Apr 22, 2026
adc8b13
fix: address PR review feedback for codeflow-mcp and codeflow-store
Copilot Apr 22, 2026
7993759
Changes before error encountered
Copilot Apr 22, 2026
919f400
Merge pull request #26 from nehraa/feature/codeflow-store-decomposition
nehraa Apr 22, 2026
eba1d41
Merge branch 'main' into feature/codeflow-mcp-decomposition
nehraa Apr 22, 2026
14838cc
Merge pull request #27 from nehraa/feature/codeflow-mcp-decomposition
nehraa Apr 22, 2026
860372f
feat(codeflow-core): add reasoning journal schemas
nehraa Apr 22, 2026
d65bcef
test(codeflow-store): add reasoning + changes test fixtures
nehraa Apr 22, 2026
890d0f1
chore: bump codeflow-core to v0.2.0 for reasoning journal feature
nehraa Apr 22, 2026
e813ed6
chore: bump codeflow-core to v1.1.0
nehraa Apr 22, 2026
68026ac
chore: set codeflow-core to v0.2.0
nehraa Apr 22, 2026
f9a814f
feat(codeflow-store): wire local codeflow-core and fix critical data …
nehraa Apr 22, 2026
15eeac9
feat: publish codeflow-core@1.1.1 with Phase 1 schema
nehraa Apr 22, 2026
52a93a0
fix: make Phase 1 fields optional for backward compat
nehraa Apr 22, 2026
9d8eedb
chore: bump codeflow-store to 0.2.4
nehraa Apr 22, 2026
a0b2129
fix(schema): add approver, runId to approvalRecord; taskId to traceSpan
nehraa Apr 22, 2026
6ac4c94
fix(store): 17 validation and API bugs across session, run, branch, a…
nehraa Apr 22, 2026
31bfc04
chore: bump codeflow-core to 1.1.5, codeflow-store to 1.0.3
nehraa Apr 22, 2026
7598d25
revert(codeflow-store): restore to v1.0.7 from npm
nehraa Apr 23, 2026
ca31fb9
fix(store): isolate test stores per module to prevent race conditions
nehraa Apr 23, 2026
7472915
release: bump version to 1.0.8
nehraa Apr 23, 2026
25c352c
docs: add codeflow-versioning 0.1.0 implementation plan
nehraa Apr 23, 2026
84df1c6
feat(versioning): scaffold package skeleton v0.1.0
nehraa Apr 23, 2026
978cfaa
feat(versioning): implement createBranch and diffBranches
nehraa Apr 23, 2026
a93c77b
feat(versioning): add src/store/index.ts re-export from codeflow-store
nehraa Apr 23, 2026
76c5e92
feat(versioning): add reasoning checkpoint snapshots
nehraa Apr 23, 2026
ec1576d
feat(versioning): add invoke.ts and diff.ts API layer
nehraa Apr 23, 2026
58a2911
feat(versioning): create barrel src/index.ts
nehraa Apr 23, 2026
a080026
feat(versioning): wire Next.js routes to import from package
nehraa Apr 23, 2026
b851ba8
feat(versioning): add CodeRAG integration (index.ts, agent.ts, search…
nehraa Apr 23, 2026
2ed7dd5
feat(versioning): add MCP tool definitions for version control
nehraa Apr 23, 2026
e5029bd
feat(versioning): add observability and risk sub-module exports
nehraa Apr 23, 2026
67b2e13
feat(versioning): wire observability, risk, session to branch creation
nehraa Apr 23, 2026
d98ae38
feat(versioning): add CodeRAG-powered observability and risk search
nehraa Apr 23, 2026
95ebfb4
feat(versioning): add observability and risk MCP tools
nehraa Apr 23, 2026
70b3c59
chore(versioning): bump version to 0.3.0
nehraa Apr 23, 2026
1d7572b
chore: add .worktrees to gitignore
nehraa Apr 24, 2026
6b0b668
feat(prd): add codeflow-prd package v0.1.0
nehraa Apr 24, 2026
77e8879
feat(agent): add core type definitions
nehraa Apr 28, 2026
8cd7ba4
feat(agent): add task queue, agent spawner, and result aggregator
nehraa Apr 28, 2026
760e8f1
fix(agent): fix markCompleted typing, add retries, add missing tests
nehraa Apr 28, 2026
ee7f142
fix(agent): use template literals in getSkillPrompt for proper interp…
nehraa Apr 28, 2026
28ac21a
feat(agent): integrate opencode CLI as backend for standalone operation
nehraa Apr 28, 2026
4e8cfb6
feat(agent): add blueprint ingestion and reasoning trace saving
nehraa Apr 28, 2026
4d46958
feat(agent): add AI orchestration layer with NVIDIA Llama blueprint g…
nehraa Apr 28, 2026
72e2669
feat(agent): add BlueprintNode language field for multi-lang support
nehraa May 8, 2026
9e4aa1e
feat(agent): add scaffold-generator and scaffold-utils — move codegen…
nehraa May 8, 2026
10f3d9e
refactor(codeflow-agent): remove duplicate types/blueprint.ts
nehraa May 8, 2026
1f713b5
feat: add execution-context, blueprint, refactor-suggester, test-gene…
nehraa May 26, 2026
375cdb8
chore: add prd change entry and update website components
nehraa May 26, 2026
1e5457e
fix(codeflow): OpenCode API Key Leaked to Child Processes
Jun 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .env
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
GEMINI_API_KEY=AIzaSyCi2AwIPaqvxI8c_reuzeSVMkUSP_3d8tg
NVIDIA_API_KEY=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
Comment on lines +1 to +2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. Committed credentials expose providers 🐞 Bug ⛨ Security

The new .env file contains literal Gemini and NVIDIA API credentials instead of placeholders or
environment references. Anyone with repository or artifact access can use them until they are
revoked, even after the file is removed from the branch because Git retains its history.
Agent Prompt
## Issue description
The PR commits live-looking Gemini and NVIDIA credentials in `.env`, exposing them through repository history and derived artifacts.

## Fix Focus Areas
- .env[1-2]
- .gitignore[9-17]

## Recommended Fix
Remove `.env` from version control, add the root `.env` file to `.gitignore`, and provide a tracked `.env.example` containing only empty, non-secret placeholders. Immediately revoke and rotate both exposed credentials.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Comment on lines +1 to +2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Remove and rotate the committed Gemini and NVIDIA keys

These non-placeholder provider credentials are tracked in the commit, so anyone with repository or fork access can use them; deleting the file in a later commit will not remove copies already fetched. Remove the file from version control and revoke/rotate both exposed credentials.

Useful? React with 👍 / 👎.

Comment on lines +1 to +2
NODE_ENV=development
99 changes: 99 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,99 @@
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL Advanced"

on:
push:
branches: [ "main" ]
pull_request:
branches: [ "main" ]
schedule:
- cron: '32 22 * * 6'

jobs:
analyze:
name: Analyze (${{ matrix.language }})
# Runner size impacts CodeQL analysis time. To learn more, please see:
# - https://gh.io/recommended-hardware-resources-for-running-codeql
# - https://gh.io/supported-runners-and-hardware-resources
# - https://gh.io/using-larger-runners (GitHub.com only)
# Consider using larger runners or machines with greater resources for possible analysis time improvements.
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
permissions:
# required for all workflows
security-events: write

# required to fetch internal or private CodeQL packs
packages: read

# only required for workflows in private repositories
actions: read
contents: read

strategy:
fail-fast: false
matrix:
include:
- language: javascript-typescript
build-mode: none
# CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift'
# Use `c-cpp` to analyze code written in C, C++ or both
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
steps:
- name: Checkout repository
uses: actions/checkout@v4

# Add any setup steps before running the `github/codeql-action/init` action.
# This includes steps like installing compilers or runtimes (`actions/setup-node`
# or others). This is typically only required for manual builds.
# - name: Setup runtime (example)
# uses: actions/setup-example@v1

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.

# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
# queries: security-extended,security-and-quality

# If the analyze step fails for one of the languages you are analyzing with
# "We were unable to automatically build your code", modify the matrix above
# to set the build mode to "manual" for that language. Then modify this step
# to build your code.
# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
- name: Run manual build steps
if: matrix.build-mode == 'manual'
shell: bash
run: |
echo 'If you are using a "manual" build mode for one or more of the' \
'languages you are analyzing, replace this with the commands to build' \
'your code, for example:'
echo ' make bootstrap'
echo ' make release'
exit 1

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
with:
category: "/language:${{matrix.language}}"
17 changes: 17 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,25 @@ node_modules
coverage
artifacts
.codeflow-store
.codeflow-store-test
.codeflow-sandboxes
.test-store
*.log
*.tsbuildinfo
.env.local
.env*.local
# CodeRag index files
.coderag-*
.coderag/

# Claude Code working directories
claude-code/
.claude/

# Serena tooling
.serena/

# Qwen Code working directories
.qwen/
.qwen*
.worktrees
84 changes: 84 additions & 0 deletions .playwright-mcp/page-2026-04-03T16-04-56-821Z.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
- generic:
- generic [active]:
- generic [ref=e3]:
- generic [ref=e4]:
- generic [ref=e5]:
- navigation [ref=e6]:
- button "previous" [disabled] [ref=e7]:
- img "previous" [ref=e8]
- generic [ref=e10]:
- generic [ref=e11]: 1/
- text: "1"
- button "next" [disabled] [ref=e12]:
- img "next" [ref=e13]
- img
- generic [ref=e15]:
- link "Next.js 16.2.1 (stale) Turbopack" [ref=e16] [cursor=pointer]:
- /url: https://nextjs.org/docs/messages/version-staleness
- img [ref=e17]
- generic "There is a newer version (16.2.2) available, upgrade recommended!" [ref=e19]: Next.js 16.2.1 (stale)
- generic [ref=e20]: Turbopack
- img
- dialog "Build Error" [ref=e22]:
- generic [ref=e25]:
- generic [ref=e26]:
- generic [ref=e27]:
- generic [ref=e29]: Build Error
- generic [ref=e30]:
- button "Copy Error Info" [ref=e31] [cursor=pointer]:
- img [ref=e32]
- button "No related documentation found" [disabled] [ref=e34]:
- img [ref=e35]
- button "Attach Node.js inspector" [ref=e37] [cursor=pointer]:
- img [ref=e38]
- generic [ref=e47]: Export default doesn't exist in target module
- generic [ref=e49]:
- generic [ref=e51]:
- img [ref=e53]
- generic [ref=e56]: ./src/components/code-editor.tsx (7:1)
- button "Open in editor" [ref=e57] [cursor=pointer]:
- img [ref=e59]
- generic [ref=e62]:
- generic [ref=e63]: Export default doesn't exist in target module
- generic [ref=e64]: 5 |
- text: import
- generic [ref=e65]: dynamic
- text: from "next/dynamic"
- generic [ref=e66]: ;
- generic [ref=e67]: 6 |
- text: import type
- generic [ref=e68]: "*"
- text: as Monaco from "monaco-editor"
- generic [ref=e69]: ;
- text: ">"
- generic [ref=e70]: 7 |
- text: import
- generic [ref=e71]: editorWorker
- text: from "monaco-editor/esm/vs/editor/editor.worker?worker"
- generic [ref=e72]: ;
- generic [ref=e73]: "|"
- text: ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
- generic [ref=e74]: 8 |
- text: import
- generic [ref=e75]: tsWorker
- text: from "monaco-editor/esm/vs/language/typescript/ts.worker?worker"
- generic [ref=e76]: ;
- generic [ref=e77]: 9 |
- generic [ref=e78]: 10 |
- text: import type
- generic [ref=e79]: "{"
- text: BlueprintGraph
- generic [ref=e80]: "}"
- text: from "@/lib/blueprint/schema"
- generic [ref=e81]: "; The export default was not found in module [project]/node_modules/monaco-editor/esm/vs/editor/editor.worker.js?worker [app-client] (ecmascript). Did you mean to import initialize? All exports of the module are statically known (It doesn't have dynamic exports). So it's known statically that the requested export doesn't exist. Import traces: Client Component Browser: ./src/components/code-editor.tsx [Client Component Browser] ./src/components/blueprint-workbench.tsx [Client Component Browser] ./src/components/blueprint-workbench.tsx [Server Component] ./src/app/page.tsx [Server Component] Client Component SSR: ./src/components/code-editor.tsx [Client Component SSR] ./src/components/blueprint-workbench.tsx [Client Component SSR] ./src/components/blueprint-workbench.tsx [Server Component] ./src/app/page.tsx [Server Component]"
- generic [ref=e82]: "1"
- generic [ref=e83]: "2"
- generic [ref=e88] [cursor=pointer]:
- button "Open Next.js Dev Tools" [ref=e89]:
- img [ref=e90]
- button "Open issues overlay" [ref=e94]:
- generic [ref=e95]:
- generic [ref=e96]: "0"
- generic [ref=e97]: "1"
- generic [ref=e98]: Issue
- alert [ref=e99]
63 changes: 63 additions & 0 deletions .playwright-mcp/page-2026-04-03T16-07-29-095Z.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
- generic [active] [ref=e1]:
- generic [ref=e2]:
- banner [ref=e3]:
- generic [ref=e4]:
- button "CodeFlow" [ref=e6] [cursor=pointer]:
- generic [ref=e7]:
- img [ref=e8]
- text: CodeFlow
- generic [ref=e23]: ▾
- generic [ref=e24]:
- button "Build" [ref=e26] [cursor=pointer]:
- text: Build
- generic [ref=e27]: ▾
- button "View" [ref=e29] [cursor=pointer]:
- text: View
- generic [ref=e30]: ▾
- button "Tools" [ref=e32] [cursor=pointer]:
- text: Tools
- generic [ref=e33]: ▾
- generic [ref=e34]:
- status [ref=e35]:
- strong [ref=e36]: Ready to build
- generic [ref=e37]: Enter a project description or repo input, then build a blueprint.
- button "Toolbar build blueprint" [ref=e38] [cursor=pointer]: Build blueprint
- generic [ref=e39]:
- generic [ref=e40]:
- generic [ref=e41]: Phase spec
- generic [ref=e42]: AI blueprint
- generic [ref=e43]: essential
- generic [ref=e44]: Checking for a server-side NVIDIA API key...
- generic [ref=e45]:
- generic [ref=e46]:
- generic [ref=e47]:
- heading "Architecture map" [level=2] [ref=e48]
- paragraph [ref=e49]: No graph yet
- button "Apply trace overlay" [disabled] [ref=e51]
- generic [ref=e52]:
- generic [ref=e53]:
- generic [ref=e54]:
- paragraph [ref=e55]: Blueprint Input
- heading "Describe what CodeFlow should build" [level=3] [ref=e56]
- paragraph [ref=e57]: A calm brief in. A clean graph out.
- img [ref=e58]
- group [ref=e73]:
- generic [ref=e74]: Input mode
- generic [ref=e75]:
- generic [ref=e76]:
- radio "AI Prompt" [checked] [ref=e77]
- text: AI Prompt
- generic [ref=e78]:
- radio "PRD / Repo" [ref=e79]
- text: PRD / Repo
- generic [ref=e80]:
- generic [ref=e81]: Describe your project
- textbox "Describe your project" [ref=e82]:
- /placeholder: A task management app with a React frontend and Node backend. Or a Rails monolith, a Django app, a Go service, a Swift iOS client, or any other stack you want to visualize.
- generic [ref=e83]:
- button "Build blueprint" [ref=e84] [cursor=pointer]
- button "Settings" [ref=e85] [cursor=pointer]: Advanced settings
- paragraph [ref=e87]: Build a blueprint from an AI prompt, PRD text, or a JavaScript/TypeScript repo.
- button "Open Next.js Dev Tools" [ref=e93] [cursor=pointer]:
- img [ref=e94]
- alert [ref=e97]
63 changes: 63 additions & 0 deletions .playwright-mcp/page-2026-04-03T16-11-20-372Z.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
- generic [active] [ref=e1]:
- generic [ref=e2]:
- banner [ref=e3]:
- generic [ref=e4]:
- button "CodeFlow" [ref=e6] [cursor=pointer]:
- generic [ref=e7]:
- img [ref=e8]
- text: CodeFlow
- generic [ref=e23]: ▾
- generic [ref=e24]:
- button "Build" [ref=e26] [cursor=pointer]:
- text: Build
- generic [ref=e27]: ▾
- button "View" [ref=e29] [cursor=pointer]:
- text: View
- generic [ref=e30]: ▾
- button "Tools" [ref=e32] [cursor=pointer]:
- text: Tools
- generic [ref=e33]: ▾
- generic [ref=e34]:
- status [ref=e35]:
- strong [ref=e36]: Ready to build
- generic [ref=e37]: Enter a project description or repo input, then build a blueprint.
- button "Toolbar build blueprint" [ref=e38] [cursor=pointer]: Build blueprint
- generic [ref=e39]:
- generic [ref=e40]:
- generic [ref=e41]: Phase spec
- generic [ref=e42]: AI blueprint
- generic [ref=e43]: essential
- generic [ref=e44]: Server environment key detected.
- generic [ref=e45]:
- generic [ref=e46]:
- generic [ref=e47]:
- heading "Architecture map" [level=2] [ref=e48]
- paragraph [ref=e49]: No graph yet
- button "Apply trace overlay" [disabled] [ref=e51]
- generic [ref=e52]:
- generic [ref=e53]:
- generic [ref=e54]:
- paragraph [ref=e55]: Blueprint Input
- heading "Describe what CodeFlow should build" [level=3] [ref=e56]
- paragraph [ref=e57]: A calm brief in. A clean graph out.
- img [ref=e58]
- group [ref=e73]:
- generic [ref=e74]: Input mode
- generic [ref=e75]:
- generic [ref=e76]:
- radio "AI Prompt" [checked] [ref=e77]
- text: AI Prompt
- generic [ref=e78]:
- radio "PRD / Repo" [ref=e79]
- text: PRD / Repo
- generic [ref=e80]:
- generic [ref=e81]: Describe your project
- textbox "Describe your project" [ref=e82]:
- /placeholder: A task management app with a React frontend and Node backend. Or a Rails monolith, a Django app, a Go service, a Swift iOS client, or any other stack you want to visualize.
- generic [ref=e83]:
- button "Build blueprint" [ref=e84] [cursor=pointer]
- button "Settings" [ref=e85] [cursor=pointer]: Advanced settings
- paragraph [ref=e87]: Build a blueprint from an AI prompt, PRD text, or a JavaScript/TypeScript repo.
- button "Open Next.js Dev Tools" [ref=e93] [cursor=pointer]:
- img [ref=e94]
- alert [ref=e97]
Loading