Comparing v2.35.6...v2.35.7 · coder/coder · GitHub
Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: coder/coder
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v2.35.6
Choose a base ref
...
head repository: coder/coder
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v2.35.7
Choose a head ref
  • 5 commits
  • 63 files changed
  • 5 contributors

Commits on Aug 26, 2026

  1. fix: prevent markdown injection in notifications (#28340) (#28611)

    Backport of #28340
    
    Original PR: #28340 — fix: prevent markdown injection in notifications
    Merge commit: 9e8075d
    Requested by: @BobbyHo
    BobbyHo authored Aug 26, 2026
    Configuration menu
    Copy the full SHA
    90970fd View commit details
    Browse the repository at this point in the history
  2. fix(coderd/notifications): HTML-escape the email template values (#28397

    ) (#28644)
    
    Backport of #28397
    
    Original PR: #28397 — fix(coderd/notifications): HTML-escape the email
    template values
    Merge commit: 2236710
    Requested by: @BobbyHo
    
    Opened manually because the Backport workflow run for `release/2.35`
    failed:
    https://github.com/coder/coder/actions/runs/32985803559/job/98231735668
    
    ## Why the automatic backport failed
    
    Two separate things went wrong in that run, and only one of them is
    about conflicts.
    
    The cherry-pick hit seven `modify/delete` conflicts (below). That alone
    is not fatal — the same happened for `release/2.36` and `release/2.37`,
    where the job still pushed a placeholder branch and opened a PR for
    manual resolution.
    
    What actually failed the job was the push:
    
    ```
    ! [remote rejected] backport/28397-to-2.35 -> backport/28397-to-2.35
      (Unable to determine if workflow can be created or updated due to timeout; `workflows` scope may be required.)
    ```
    
    This cherry-pick touches no files under `.github/workflows/`, so this is
    GitHub timing out while determining scope rather than a genuine
    permission gap. The push was retried by hand for this PR and succeeded
    unchanged. The net effect of the failure was that no branch and no PR
    were created for 2.35 at all, so this one is opened from scratch rather
    than fixed up in place.
    
    ## Manual resolution: 7 golden files dropped
    
    `release/2.35` already carries #28611 (the 2.35 backport of #28340), so
    the `notifier.go` hunk applies cleanly. What remains is a genuine
    `modify/delete` conflict on seven golden files:
    
    ```
    TemplateAIBudgetLimitReachedUser.html.golden
    TemplateAIBudgetWarningUser.html.golden
    TemplateUserAccountActivatedServiceAccount.html.golden
    TemplateUserAccountCreatedServiceAccount.html.golden
    TemplateUserAccountCreatedWithoutAccountType.html.golden
    TemplateUserAccountDeletedServiceAccount.html.golden
    TemplateUserAccountSuspendedServiceAccount.html.golden
    ```
    
    These are fixtures for the AI budget and service-account notification
    templates, both of which postdate the 2.35 branch point.
    `coderd/notifications/` on `release/2.35` contains no reference to
    `AIBudget`, `BudgetLimitReached`, `BudgetWarning`, `ServiceAccount` or
    `AccountType`, so there is no template to render them and no test case
    that reads them. **All seven were removed rather than added**; carrying
    them over would leave orphan fixtures.
    
    This is the only deviation from the original PR. Verified with a
    diff-of-diffs: excluding those seven paths, this commit is
    byte-identical to #28397. The escaping changes to `html.gotmpl`,
    `notifier.go` and `smtp_internal_test.go` are fully intact.
    
    Net: 32 files, +230/−75 (upstream: 39 files, +244/−89 — the delta is
    exactly the seven goldens). The smtp golden directory holds 38 files
    before and after, so nothing was added or lost.
    
    ## Verification
    
    - `go vet ./coderd/notifications/...` — clean
    - `go test ./coderd/notifications/dispatch/...` — pass, including the
    three new `TestSMTPHTMLTemplateEscapes*` tests
    - `go test ./coderd/notifications/ -run
    TestNotificationTemplates_Golden` — pass across all affected goldens
    
    ## Related backports
    
    - #28603 — `release/2.37`
    - #28604 — `release/2.36`
    - #28643 — `release/2.29` (still needs manual resolution)
    BobbyHo authored Aug 26, 2026
    Configuration menu
    Copy the full SHA
    fcacdea View commit details
    Browse the repository at this point in the history
  3. fix(coderd): reject agent requests from suspended owners (#28513) (#2…

    …8653)
    
    Backport of #28513
    
    Original PR: #28513 — fix(coderd): reject agent requests from suspended
    owners
    Merge commit: 2f50b2d
    Requested by: @hwang251
    
    Co-authored-by: Marcin Tojek <mtojek@users.noreply.github.com>
    hwang251 and mtojek authored Aug 26, 2026
    Configuration menu
    Copy the full SHA
    5a07bdf View commit details
    Browse the repository at this point in the history

Commits on Aug 27, 2026

  1. fix: enable Copilot HTTP transport fallback (#28494) (#28722)

    Backport of #28494
    
    Original PR: #28494 — fix: enable Copilot HTTP transport fallback
    Merge commit: 849543d
    Requested by: @ssncferreira
    
    > [!NOTE]
    > This pull request was generated by Coder Agents on behalf of
    @ssncferreira.
    ssncferreira authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    d8e69d3 View commit details
    Browse the repository at this point in the history

Commits on Sep 1, 2026

  1. chore: purge identified terraform modules via dbpurge (#28802) (#28814)

    Cherry-pick of [#28802](#28802)
    (`e2a856d42b`), matching
    [#28810](#28810) for `release/2.37`.
    
    Deletes cached Terraform module archives ingested during the identified
    window and clears the template version references to them. Runs from
    `dbpurge` rather than a migration, because migrations cannot be
    backported: the version table records a single high-water mark, so a
    migration cherry-picked here would cause later upgrades to skip every
    migration in between.
    
    ## Conflict resolution
    
    The commit did not apply cleanly. This branch predates the chat search
    work on `main`, so the incoming hunks carried unrelated context that was
    dropped:
    
    - `dbpurge.go`: took only the module cache block, the
    `ranModuleCachePurge` latch, the window constants, the
    `identified_module_files` log field and metric, and the
    `identifiedModuleCachePurged` instance field. Dropped the
    `chat_messages.search_tsv` backfill and stale reindex, along with
    `staleDrained` and the `chatSearch*` fields, none of which exist on this
    branch.
    - `dbpurge_test.go`: took `TestDeleteIdentifiedModuleCacheFiles` and the
    `awaitDoTicks` helper it depends on. Dropped
    `TestBackfillChatMessagesSearchTsv`. In the two `TestMetrics` mock
    setups, added only the `DeleteCachedModuleFilesCreatedBetween`
    expectation.
    - Generated files (`querier.go`, `queries.sql.go`, `dbmetrics`,
    `dbmock`, and the `dbauthz` stub) were reset to the branch state and
    regenerated from `queries/files.sql`, rather than taking the diff from
    `main`. Taking `main`'s versions would have introduced methods for
    queries that do not exist on this branch.
    
    ## Testing
    
    `coderd/database/dbpurge` and `TestMethodTestSuite` in
    `coderd/database/dbauthz` pass against Postgres. `make gen` is clean and
    pre-commit hooks pass.
    
    ---
    
    Opened by Coder Agents on behalf of @Emyrk.
    Emyrk authored Sep 1, 2026
    Configuration menu
    Copy the full SHA
    7b95f85 View commit details
    Browse the repository at this point in the history
Loading