Skip to content

chore: consolidate dependency updates, clear npm audit, fix per-model param docs - #132

Merged
justin-carper merged 3 commits into
mainfrom
chore/maintenance-sweep
Sep 30, 2026
Merged

justin-carper merged 3 commits into
mainfrom
chore/maintenance-sweep

Conversation

@justin-carper

Copy link
Copy Markdown
Collaborator

Summary

Supersedes Dependabot PRs #122, #124 and #125 with one verified update, clears npm audit, and fixes the misleading docs behind #119.

Dependencies

Docs (#119)

Cursor model param ids are per model. grok-4.6 exposes effort, not thinking, so a configured thinking param is sent and ignored, and Cursor uses its default (high). That last step is inferred from the report, not proven from code.

  • README: corrected the params example, added a per-model param note, reworded the cursor_delegate / cursor_cloud_agent thinking rows.
  • src/plugin/cursor-tools.ts: the two thinking describe() strings the model sees.
  • Comment-only edits in src/provider/{controls,delegate,cloud-agent,index}.ts.
  • No logic change.

Verification

  • npm ci from scratch, npm run typecheck, npm run build: pass
  • npm test: 42 files / 642 tests pass (same as baseline on main)
  • npm audit: 0 vulnerabilities
  • bash scripts/integration-test.sh against a real opencode 1.18.33: plugin loads, lists Cursor models, limit.input sentinel intact, delegation tools register
  • Lockfile: every resolved URL is registry.npmjs.org

Closes nothing automatically; #119 and #126 need replies (see notes).

… param docs

Dependencies (supersedes #122, #124, #125):
- @connectrpc/connect-node 2.1.2 -> 2.2.0
- @cursor/sdk 1.0.31 -> 1.0.32
- @opencode-ai/plugin + sdk -> 1.18.33 (one sdk copy)
- @ai-sdk/provider 3.0.15 -> 3.0.18, @types/node -> 26.6.3, vitest -> 5.0.2
- overrides: undici ^6.28.1 (GHSA-3wwx-pv8p-q78v), new toml ^4.2.0
  (GHSA-82x6-q7mm-w9cf); npm audit reports 0 vulnerabilities
- @ai-sdk/provider v4 and TypeScript 7 stay blocked per dependabot.yml

Docs (#119): Cursor model param ids are per model, so `thinking` on a
model without that param (e.g. grok-4.6, which takes `effort`) is ignored.
Correct the README examples and the delegate/cloud-agent `thinking`
tool-arg descriptions. Comment-only changes in src/provider; no logic change.
…x fallback param

- README (#126): the opencode v2 install snippet used @latest, which is
  0.9.0 (v1-only build, no { id, setup } default export) and reproduces
  "Plugin must export a default definition" on opencode 2.x. Point it at
  @next until 0.10.0 is promoted, with a note.
- cursor_refresh_models (#119): append each model's param ids and accepted
  values, e.g. `grok-4.6 [effort=low|medium|high|xhigh, fast=false|true]`,
  so users can tell effort from reasoning_effort. Add a test.
- fallback catalog: composer-2.5 exposes `fast`, not `thinking`; the stale
  entry produced a bogus `thinking` variant on the keyless path.
- CHANGELOG: limit the connect-node note to verified facts (nothing in the
  repo imports it; @cursor/sdk nests its own 1.7.0) and record the above.
The troubleshooting entry and the manual-install snippet only described the
opencode v1 cache layout (~/.cache/opencode/packages/...). opencode v2 caches
plugin installs under ~/.cache/opencode/npm/<spec>/, so anyone following the
README on v2 cleared the wrong directory (#126). Cover both layouts, point v2
users at `opencode plugin update`, and note that an @latest install of 0.9.x
has no v2 entrypoint.
@justin-carper
justin-carper merged commit 4945160 into main Sep 30, 2026
8 checks passed
@justin-carper
justin-carper deleted the chore/maintenance-sweep branch September 30, 2026 11:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant