chore(acp): bump dimcode and grok registry pins to probed versions - #973
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Scheduled ACP Registry version sync. Two npx pins drifted since #971, each backed by a fresh serial ACP probe of the exact pinned version. This is a single-file diff: neither outgoing version appears in any test assertion, and codebuddy — the only package whose version is embedded in one — did not drift.
dimcode-32000, "Provider credentials are required")@xai-official/grok-32000, "no auth method id provided")Both meet the release-lock criterion:
initializesucceeds andsession/newreturns a clearly classified authentication requirement. Probes ran serially with no inherited HOME or credentials. dimcode still self-reportsagentInfo.titleas "DimAgent" against a public listing of "DimCode" — a standing vendor quirk, not an AionCore defect.Snapshot structural diff: the previous snapshot (
v2026.09.07-50f99cd, audited earlier the same day) was still on disk, so the per-agent comparison ran. Across all 39 agents the only changes are these two npx package versions — no distribution type added or removed, noargs/envchange anywhere, and no binary artifact movement this window. Nothing outside the lock needed reporting.Derived-assertion scan: both outgoing versions (
0.3.28,1.0.21) were scanned acrosscrates/**/*.rswith fixed-string matching before staging; neither has a single hit.registry_npx_lock.rsstill pins codebuddy at2.146.0, which is correct for this snapshot.npx_cache_repair.rskeeps its own version literals: those are cache-path hash fixtures, not lock assertions.The other 9 Registry-pinned packages (autohand, codebuddy, deepagents, dirac, glm-acp-agent, kilo, nova, pi, sigit) match the snapshot exactly. Drifted but not upgraded: none.
mimo-coderemains the one non-Registry builtin (noregistry_json_id), excluded from drift reconciliation.Standing watch (unchanged, no action in this PR): sigit's ACP probe announced an npm scope rename (
@smbcloud/sigit→@getsigit/sigit) on 2026-09-07. The Registry still declares the old scope, so the pin is untouched; the eventual switch needs a metadata migration alongside the lock, becauseagent_metadataseeds the launch args as["-y","@smbcloud/sigit"](migration 025). That will be a human-reviewed PR.Registry snapshot
v2026.09.07-aafb17aofagentclientprotocol/registry, fetched via the versioned CDN path for reproducibility.antigravity-acpremains listed and deferred as binary-only since 2026-08-21;fast-agentandminion-coderemain listed but uvx-only and therefore out of scope.)Validation
just migration-check— passjust lint-fix(cargo fix+clippy --fix --workspace -D warnings) — cleanjust fmt— cleancargo nextestintentionally skipped, by standing policy for lock-only bumps (established 2026-08-11). The Test check on this PR is the authority for this change: the merge decision depends on CI rather than the local run, and this host's load only manufactures timeout-shaped test failures, which nothing in the local steps above is subject to.Logging
No logging changes: this is a lock version bump only; existing startup/session error paths already identify a failing agent by backend.