Skip to content

udpate gui-chat-plugin - #192

Merged
isamu merged 3 commits into
mainfrom
gui-chat-plugin-20260722
Jul 21, 2026
Merged

udpate gui-chat-plugin#192
isamu merged 3 commits into
mainfrom
gui-chat-plugin-20260722

Conversation

@isamu

@isamu isamu commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • Chores
    • Updated GUI Chat and MulmoChat plugin packages to newer versions.
    • Updated the GUI Chat protocol package to version 1.1.0.
    • Updated the tar resolution to 7.5.18.

@socket-security

socket-security Bot commented Jul 21, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​mulmochat-plugin/​ui-image@​0.4.0 ⏵ 0.4.17010083 +389 +1100
Updated@​gui-chat-plugin/​scroll-to-anchor@​0.4.0 ⏵ 0.5.17110088 +292 +1100
Updated@​gui-chat-plugin/​edit-image@​0.4.1 ⏵ 0.5.1721009892 +1100
Updated@​gui-chat-plugin/​set-image-style@​0.4.0 ⏵ 0.5.17210089 +292 +1100
Updated@​mulmochat-plugin/​generate-image@​0.4.1 ⏵ 0.5.17210087 +294100
Updated@​gui-chat-plugin/​switch-role@​0.4.0 ⏵ 0.5.17210093 +292 +1100
Updated@​gui-chat-plugin/​generate-html@​0.4.0 ⏵ 0.5.17210091 +292 +1100
Updated@​gui-chat-plugin/​edit-html@​0.4.0 ⏵ 0.5.17310091 +292 +1100
Updated@​gui-chat-plugin/​browse@​0.4.0 ⏵ 0.5.1731009892 +1100
Updated@​gui-chat-plugin/​exa@​0.4.0 ⏵ 0.5.1731009892 +1100
Updated@​mulmochat-plugin/​summarize-pdf@​0.4.1 ⏵ 0.5.17310087 +293100
Updated@​gui-chat-plugin/​camera@​0.4.1 ⏵ 0.5.173 +110090 +292 +1100
Updated@​gui-chat-plugin/​canvas@​0.4.1 ⏵ 0.5.17310092 +293100
Updated@​gui-chat-plugin/​text-response@​0.4.0 ⏵ 0.5.173 +110099 +192 +1100
Updated@​gui-chat-plugin/​html@​0.4.0 ⏵ 0.5.17410092 +291 +1100
Updated@​gui-chat-plugin/​spreadsheet@​0.4.0 ⏵ 0.5.174 +110099 +192 +1100
Updated@​gui-chat-plugin/​todo@​0.4.0 ⏵ 0.5.1741009892 +1100
Updated@​gui-chat-plugin/​othello@​0.4.0 ⏵ 0.5.174 +11009992 +1100
Updated@​gui-chat-plugin/​mindmap@​0.4.1 ⏵ 0.5.17410099 +192 +1100
Updated@​mulmochat-plugin/​quiz@​0.4.3 ⏵ 0.5.174 +110098 +194100
Updated@​gui-chat-plugin/​drawing-game@​0.4.0 ⏵ 0.5.1751009891 +1100
Updated@​gui-chat-plugin/​weather@​0.4.0 ⏵ 0.5.175 +110098 +292 +1100
Updated@​gui-chat-plugin/​tictactoe@​0.4.0 ⏵ 0.5.175 +11009892 +1100
Updated@​gui-chat-plugin/​go@​0.4.0 ⏵ 0.5.175 +11009992 +1100
Updated@​gui-chat-plugin/​mulmocast@​0.4.1 ⏵ 0.5.175 +110098 +192100
Updated@​gui-chat-plugin/​google-map@​0.4.1 ⏵ 0.6.175 +110098 +194 +2100
Updatedgui-chat-protocol@​0.3.3 ⏵ 1.1.075 -1100100 +193 -1100
Updated@​mulmochat-plugin/​form@​0.5.1 ⏵ 0.6.175 +110088 +293100
Updated@​gui-chat-plugin/​markdown@​0.4.0 ⏵ 0.5.176 +110099 +192100
Updated@​gui-chat-plugin/​music@​1.2.0 ⏵ 1.3.177 +41009992100
Updated@​gui-chat-plugin/​avatar@​0.4.0 ⏵ 0.5.179 +110099 +192 +1100
Updated@​gui-chat-plugin/​present3d@​0.4.0 ⏵ 0.5.179 +610099 +192 +2100
See 4 more rows in the dashboard

View full report

@socket-security

socket-security Bot commented Jul 21, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @noble/hashes is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: yarn.locknpm/@gui-chat-plugin/mulmocast@0.5.1npm/@noble/hashes@1.8.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@noble/hashes@1.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @noble/hashes is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: yarn.locknpm/@gui-chat-plugin/mulmocast@0.5.1npm/@noble/hashes@1.8.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@noble/hashes@1.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm pdfkit is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: yarn.locknpm/@gui-chat-plugin/mulmocast@0.5.1npm/pdfkit@0.18.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/pdfkit@0.18.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@coderabbitai

coderabbitai Bot commented Jul 21, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 327afef7-65f7-4e6c-bdd6-ac33059fd1c3

📥 Commits

Reviewing files that changed from the base of the PR and between 4d0d1de and a2ff933.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • package.json

📝 Walkthrough

Walkthrough

Updated package.json dependencies for GUI chat plugins, MulmoChat plugins, and gui-chat-protocol, including a protocol version change from ^0.3.3 to ^1.1.0, and bumped the tar resolution.

Changes

Dependency updates

Layer / File(s) Summary
Package dependency versions
package.json
Bumps GUI chat, MulmoChat plugin, and gui-chat-protocol packages, and updates the tar resolution to 7.5.18.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is clearly related to the main change, which updates gui-chat-plugin dependencies.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch gui-chat-plugin-20260722

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@package.json`:
- Line 79: Update the `@gui-chat-plugin/`* and `@mulmochat-plugin/`* dependency
versions so their peer dependencies accept gui-chat-protocol ^1.1.0, including
`@gui-chat-plugin/piano`’s protocol range, before retaining the gui-chat-protocol
^1.1.0 entry. Otherwise, keep gui-chat-protocol on the older compatible range.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 350b42d1-5ce6-4d0b-93a6-4331accf814c

📥 Commits

Reviewing files that changed from the base of the PR and between 0356bdc and 4d0d1de.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Comment thread package.json
"exa-js": "^2.1.1",
"express": "^5.2.1",
"gui-chat-protocol": "^0.3.3",
"gui-chat-protocol": "^1.1.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

jq -r '
  .dependencies
  | to_entries[]
  | select(.key | test("^@(gui-chat-plugin|mulmochat-plugin)/"))
  | select(.value | test("^(\\^|~)?[0-9]"))
  | "\(.key)\t\(.value | sub("^[\\^~]"; ""))"
' package.json |
while IFS=$'\t' read -r package version; do
  encoded=$(jq -nr --arg package "$package" '$package | `@uri`')
  printf '\n%s@%s\n' "$package" "$version"
  curl -fsSL "https://registry.npmjs.org/${encoded}/${version}" |
    jq '{peerDependencies, peerDependenciesMeta}'
done

Repository: receptron/MulmoChat

Length of output: 149


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf 'package.json context:\n'
jq -r '
  .dependencies
  | to_entries[]
  | select(.key | test("^@(gui-chat-plugin|mulmochat-plugin)/|^gui-chat-protocol$"))
  | "\(.key)\t\(.value)"
' package.json

printf '\nsearching repository for protocol/plugin references:\n'
rg -n --hidden --glob '!node_modules' --glob '!dist' --glob '!build' --glob '!coverage' \
  'gui-chat-protocol|`@gui-chat-plugin/`|`@mulmochat-plugin/`' .

printf '\nworkspace/package manifests:\n'
fd -a 'package.json' .

printf '\nlockfile entries (if present):\n'
fd -a 'package-lock.json|pnpm-lock.yaml|yarn.lock' .

Repository: receptron/MulmoChat

Length of output: 45751


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Show the relevant package entries and any lockfile-encoded package metadata.
python3 - <<'PY'
import json, pathlib, re
pkg = json.loads(pathlib.Path('package.json').read_text())
for k,v in pkg.get('dependencies', {}).items():
    if k == 'gui-chat-protocol' or re.match(r'^@(gui-chat-plugin|mulmochat-plugin)/', k):
        print(f'{k}\t{v}')
PY

# Search for plugin manifests and protocol constraints in the repo.
rg -n --hidden --glob '!node_modules' --glob '!dist' --glob '!build' --glob '!coverage' \
  'gui-chat-protocol|peerDependencies|`@gui-chat-plugin/`|`@mulmochat-plugin/`' .

# List likely manifest files.
fd -a 'package.json' .
fd -a 'pnpm-lock.yaml|package-lock.json|yarn.lock' .

Repository: receptron/MulmoChat

Length of output: 46204


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Inspect only local metadata first.
for f in package.json package-lock.json pnpm-lock.yaml yarn.lock; do
  [ -f "$f" ] && printf '\n== %s ==\n' "$f"
done

printf '\npackage.json dependencies of interest:\n'
python3 - <<'PY'
import json, pathlib, re
pkg = json.loads(pathlib.Path('package.json').read_text())
deps = pkg.get('dependencies', {})
for k in sorted(deps):
    if k == 'gui-chat-protocol' or re.match(r'^@(gui-chat-plugin|mulmochat-plugin)/', k):
        print(f'{k}\t{deps[k]}')
PY

printf '\nlocal mentions of gui-chat-protocol / plugin packages:\n'
rg -n --hidden --glob '!node_modules' --glob '!dist' --glob '!build' --glob '!coverage' \
  'gui-chat-protocol|`@gui-chat-plugin/`|`@mulmochat-plugin/`' package.json package-lock.json pnpm-lock.yaml yarn.lock . 2>/dev/null || true

Repository: receptron/MulmoChat

Length of output: 50375


Update the plugin protocol range before bumping gui-chat-protocol.
The current @gui-chat-plugin/* and @mulmochat-plugin/* versions still peer-depend on gui-chat-protocol "^0.4.0" (and @gui-chat-plugin/piano on ^0.0.3), so they won’t accept 1.1.0. Upgrade those plugins or keep the older protocol range.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@package.json` at line 79, Update the `@gui-chat-plugin/`* and
`@mulmochat-plugin/`* dependency versions so their peer dependencies accept
gui-chat-protocol ^1.1.0, including `@gui-chat-plugin/piano`’s protocol range,
before retaining the gui-chat-protocol ^1.1.0 entry. Otherwise, keep
gui-chat-protocol on the older compatible range.

@isamu
isamu merged commit f05a6cb into main Jul 21, 2026
12 checks passed
@isamu
isamu deleted the gui-chat-plugin-20260722 branch July 21, 2026 21:26
@coderabbitai coderabbitai Bot mentioned this pull request Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant