Outstanding work only. When an item is done, delete it in the same commit and add a #done entry to docs/updates/ (format and query commands: docs/updates/README.md). No finished items, no history, no rules (rules live in CLAUDE.md).
Item numbers (#n) are never reused. Tags: [DECIDE] needs the owner's decision, [BLOCKED] waits on something else, [UNVERIFIED] observed but not confirmed.
Cross-repo and workspace items live in D:\Codes\progress.md (relevant here: X-1, X-13, X-17).
- #2 [DECIDE] Closing one run window leaves its child running, with no window; only Run > Stop All Program, which stops every run (
PyBreezeMainWindow.stop_all_runs), or closing the whole IDE stops it (PyBreezeMainWindow.closeEvent,pybreeze/pybreeze_ui/editor_main/main_ui.py). Should closing a run window stop its run (CodeWindow.stop_runner()exists;CodeWindow.closeEventtoday only lets the main window forget a finished one), ask first, or keep going on purpose (for example a long load test that mails its report)? - #27 [DECIDE] paramiko is not pinned (
requirements.txt,pyproject.toml,dev.toml), so an install may get 4.x, which still has CVE-2026-44405 (SHA-1 RSA signatures). The code refuses SHA-1 on every connect whatever the version (SHA1_ALGORITHMS, U-20260923-40), and the SSH tests pass on 5.0.0. Should the dependency sayparamiko>=5.0.0, or be pinned exactly like PySide6? - #49 [DECIDE] jupyterlab is unpinned (
requirements.txt,pyproject.toml,dev.toml) and the JupyterLab tab installs it only when it is missing (jupyter_lab_gui/jupyter_lab_thread.py,is_jupyter_installed), so an existing environment keeps whatever jupyter_server it has; this repo's.venvhas 2.17.0. Fixed upstream: path traversal (CVE-2026-5422, fixed in 2.18.2), stored XSS through the nbconvert handlers (CVE-2026-44727 / GHSA-fcw5-x6j4-ccmp, 2.20.0; the embedded server has no token, so a script in a rendered notebook can drive it) and tokens logged from the Referer on 5xx (CVE-2026-86049, 2.21.0). jupyterlab itself is 4.5.6 there, below the fixes for a sanitizer-allowed command-linker button that runs commands on one click (CVE-2026-42557, 4.5.7), an SVG opened in the image viewer keeping a same-origin script context (CVE-2026-73415) and an importedoverrides.json(CVE-2026-73417), both fixed in 4.5.10 / 4.6.2; with no token, a script running in the page can drive the server. Should the dependencies requirejupyter_server>=2.21.0andjupyterlab>=4.5.10, and should the tab check the installed version and offer to upgrade? - #53 [DECIDE]
requestsandurllib3are imported directly (utils/network/public_http.py,http_client.py,url_validation.py, the three AI panels) but declared nowhere (requirements.txt,pyproject.toml,dev.toml); they arrive through the automation packages, so their versions are whatever those allow. This repo's.venvhas urllib3 2.6.3, below the 2.7.0 that fixes CVE-2026-44431 (Authorization and Cookie forwarded on a cross-origin redirect; these requests do not follow redirects) and CVE-2026-44432 (a Brotli response decompressed whole on a secondread(amt); not reproduced here with brotli 1.2.0 installed,read_capped_textstopped at its 16 MB cap).public_httpalso relies on urllib3's_dns_hostandhttp.client's_create_connection(test_public_http.pyguards both; passes on urllib3 2.6.3 and 2.8.0).cryptographyis imported directly too (connect_gui/ssh/ssh_key_loader.py, reading PKCS#8 and passphrase-protected keys) and arrives only through paramiko; the.venvhas 46.0.6, below 46.0.7, which fixes CVE-2026-39892 (a non-contiguous buffer passed to an API that takes one, such asHash.update(buf[::-1]); the key loader passes wholebytes). So isqt_material, whichstart_editorneeds to style the window (editor_main/main_ui.py) and which arrives only through je-editor;idna(utils/network/url_validation.py) is imported with a fallback. Should the dependencies declarerequests,urllib3>=2.7.0,cryptography>=46.0.7andqt-material, and pin them like PySide6? - #54 [DECIDE] The release path trusts more than it needs to.
stable.yml'spublishjob uploads with a long-livedsecrets.PYPI_API_TOKEN(.github/workflows/stable.yml:136-140); PyPI's trusted publishing (OIDC,pypa/gh-action-pypi-publishwithid-token: write) would need no stored token, but it has to be set up on PyPI by the owner first. Every action indev.ymlandstable.ymlis pinned by a movable tag (actions/checkout@v4,SonarSource/sonarqube-scan-action@v8.2.1, ...), not a commit SHA, and the job holding the PyPI token andcontents: writeruns them. CI also installs prthinker from the head of itsmainbranch (dev.yml:39,stable.yml:39). Should the publish job move to trusted publishing and the actions be pinned by SHA? - #89 [DECIDE] The prthinker settings offer the Gemini, Cohere and Mistral backends but have no field for their keys: prthinker reads
PRTHINKER_GEMINI_API_KEY/_COHERE_/_MISTRAL_from the environment the IDE was started in (astest_prthinker_contract.pynotes), so choosing one of them in the dialog alone always fails for want of a key (dialog/prthinker_setting_dialog.py,extend/prthinker_extend/prthinker_setting.py). Should they get password fields like the OpenAI and Anthropic keys, or the dialog say where the key comes from? Related: a saved backend, platform or RAG value the dialog does not list is shown as the first item and replaced on the next Save, on purpose (test_a_stored_value_that_is_not_on_offer_leaves_the_first_choice); a newer prthinker's value is lost that way. Keep it, or list the unknown value? - #92 [DECIDE] The embedded JupyterLab has no token (
--ServerApp.token=): the loopback bind keeps browsers and other machines out, but not other accounts on a shared machine (RDS, a lab Linux box), which get a kernel as the IDE user. Generate a token per launch and load the view with it? The Security › JupyterLab rule would change with it. - #102 [BLOCKED] A report mail can wait forever: je_mail_thunder's
SMTPWrapper(host, port)passes no timeout toSMTP_SSL, so a mail server that accepts the connection and then stalls holds the report-mail thread (extend/mail_thunder_extend/mail_thunder_setting.py,send_report) with no end, and the run window never says whether the report went. Needs atimeoutargument in MailThunder (je_mail_thunder/smtp/smtp_wrapper.py:20); then pass 30 s here. - #103 [BLOCKED] PyBreeze's automation keywords are never highlighted:
syntax_extend_packageregisters them for.json,.ymland.yaml(pybreeze_ui/syntax/syntax_extend.py), but JEditor has built-in rules for those suffixes, soCodeEditor.reset_highlightergets aGenericHighlighterfromhighlighter_for, and onlyPythonHighlighterreads the plugin registry (je_editor/pyside_ui/code/syntax/generic_syntax.py:124,code_edit_plaintext.py:423-425inD:\Codes\JEDITORat d372c35). Needs JEditor's generic highlighter to add a registered language's words for the suffix, taking the colour as a theme colour key as its own rules do (PyBreeze registerswarning_output_coloranddiff_modified_marker_color); thearchitecture.md§6 contract changes with it. - #106 [DECIDE]
test_pioneeris unpinned (requirements.txt,pyproject.toml,dev.toml), and before 0.1.34 it read a YAML file in the locale's encoding: on a Traditional Chinese Windows (cp950) TestPioneer "Run YAML" of a file with a non-ASCII character, which the editor saves as UTF-8, exits 1 withUnicodeDecodeError(extend/process_executor/test_pioneer/test_pioneer_process_manager.py). This repo's.venvhas 0.1.30; 0.1.34 reads it as UTF-8.Install ▸ Automation ▸ Install TestPioneerupgrades it by hand meanwhile. Should the dependencies requiretest_pioneer>=0.1.34? - #108 [BLOCKED] The Traditional Chinese IDE still shows Mainland terms in JEditor's own entries, which PyBreeze does not define: the Run menu (
run_menu_label運行,run_menu_run_program_label運行程式,run_menu_run_on_shell_label在終端運行, ...), the font menus (file_menu_font_label/text_menu_label_font字體,font_size字體大小) andeditor_code_result程式運行結果 (je_editor/utils/multi_language/traditional_chinese.py:54,:96-97and on, inD:\Codes\JEDITORat e1a8b12). PyBreeze's own entries use 執行, 字型, 外掛 and 終端機 (test_traditional_chinese_uses_taiwan_terms), so its menus now sit beside JEditor's 運行. The Dock menu is 區域 (dock_menu_label, with 新編輯器區域, 新瀏覽器區域,:64-68at bb6bc94) while PyBreeze's entries in it say 停駐窗格, and its Editor, Git and Tools submenus (:78-80) are not translated. Needs the words changed in JEditor; overriding them here would copy JEditor's English entries into both of PyBreeze's dictionaries. - #109 [DECIDE]
je-editor>=1.0.27(requirements.txt,pyproject.toml,dev.toml) lets an environment keep a gitpython below 3.1.59, which has CVE-2026-78676 (a config write turns a quoted value into a livecore.hooksPath: code runs on the next hook) and CVE-2026-78679; the IDE's git features use it (JEditor'sje_editor/git_client/). je-editor 1.0.28 differs from 1.0.27 only in requiringgitpython>=3.1.59, and 3.1.59 still has CVE-2026-87818 (the diff API's--no-indexreads any path), fixed in 3.1.60. Should the dependencies sayje-editor>=1.0.28, declaregitpython>=3.1.60, or both? JEditor's own floor is its to raise (D:\Codes\JEDITOR\pyproject.toml:18). - #110 [BLOCKED] A file opened from the project tree shows as unsaved (" *" on its tab,
_is_modifiedtrue) before anything is typed: JEditor'sEditorWidget.open_an_filefills the editor withsetPlainText, which fires_on_text_changed, and never clears the mark afterwards (je_editor/pyside_ui/main_ui/editor/editor_widget.py:295and:347-358inD:\Codes\JEDITORat 1bf81e3; plainEditorMaindoes the same). Needsopen_an_fileto clear the mark (mark_saved()) once the file is loaded. - #111 [DECIDE] AI Code Review, CoT Code Review and Skill Send refuse an endpoint on this machine or on a private network (
validate_urlinai_code_review_gui.py:77,code_review_thread.py:33,skills_send_gui.py:55;url_validation._is_blocked_ip), so a local model server (Ollama, LM Studio, a prthinker server on localhost) cannot be used from them, although CoT Code Review and Skill Send suggestedhttp://127.0.0.1:5000/apiuntil U-20260925-11. The Security › Network rule rejects loopback and private addresses for every user-supplied URL. Should these panels let the user allow a loopback (or private) endpoint, for example after a confirmation naming the address, or stay public-only? - #112 [DECIDE] Two of the executable build configs still build the IDE under its old name:
exe/auto_py_to_exe_setting_linux.json(name AutomationIDE, scriptexe/start_automation_editor.pyand iconexe/je_driver_icon.ico, neither of which exists any more, all underC:/CodeWorkspace/Python/AutomationIDE) and the InstallForge projectexe/automation_ide_setup_config.ifp(program AutomationIDE 1.0.9, the AutomationIDE repository as its website and licence link, the same icon,...\AutomationIDE\output\AutomationIDE.exe). The Windowsexe/auto_py_to_exe_setting.jsonbuilds PyBreeze fromexe/start_pybreeze.pywith the iconpybreeze/pybreeze_ui/editor_main/pybreeze_icon.ico, also bundled as data for the window. Should the two be brought over to PyBreeze the same way (their paths are a build machine's), or deleted if they are no longer used? - #113 [BLOCKED] A translation plugin's language is listed in the Language menu under its key, not the name it registers:
register_natural_language(key, display_name, word_dict)(je_editor/plugins/__init__.py) writes the dictionary intolanguage_wrapper.choose_language_dictbut notdisplay_names, soavailable_languages()lists it anddisplay_name()gives the key (je_editor/pyside_ui/main_ui/menu/language_menu/build_language_server.py:47-49), and the loop overget_all_natural_languages()below skips it as already listed. Seen with the Sphinx Plugins page's French example ("French" shown, not "Français") on je_editor 1.0.27. Needs JEditor'sregister_natural_languageto calllanguage_wrapper.register_language(key, word_dict, display_name). - #114 [BLOCKED] File > Save File, Run Program and Run Debugger open a Save As dialog every time, starting in the working folder with no name filled in, even for a tab that already has a file: each calls
choose_file_get_save_file_path()(je_editor/pyside_ui/main_ui/menu/file_menu/build_file_menu.py:96,.../run_menu/under_run_menu/build_program_menu.py:95,build_debug_menu.py:106), which always asks, on je_editor 1.0.27. PyBreeze's own Run with... saves in place (save_current_file_for_run). Needs JEditor to write a tab with a file where it is, and ask only for one without; the Sphinx File/Run/Text page says what it does now. - #115 [BLOCKED] Run Debugger works once per editor tab: when the
pdbrun ends,ExecManager.full_exit_program()clears the tab'sexec_program, notexec_python_debugger(je_editor/pyside_ui/code/code_process/code_exec.py:228), and nothing else clears it, not Stop current program (build_run_menu.py:117) or Stop All, so the next Run Debugger in that tab says a program is still running (build_debug_menu.py:102). Reproduced on je_editor 1.0.27 in the real window: afterpdbquit (exit 0) the slot was still set and a second Run Debugger was refused. Needs the debugger's manager to clear the slot it was stored in. - #116 [BLOCKED] Opening a file into an editor tab replaces the text it holds without asking: a click in the project tree (
project_treeview.clicked->treeview_click) and File > Open File both callEditorWidget.open_an_file()(je_editor/pyside_ui/main_ui/editor/editor_widget.py:262), which checks only whether the file is open elsewhere, thensetPlainTexts it. A tab with a file loses the last seconds of typing (auto-save runs every 5 s); a new tab loses everything. Reproduced on je_editor 1.0.27 in the real window: an untitled tab's text was replaced, nothing asked. Needs JEditor to ask when the tab has unsaved edits (its_is_modified), or open into a new tab; the Sphinx UI Overview says what happens now. - #117 [BLOCKED] JEditor's Variable Inspector (Tab > Tools Tab, Dock > Editor, and each editor tab's bottom panel) is always empty:
VariableModelshows thenamespaceit is given, and nothing gives it one (je_editor/pyside_ui/code/variable_inspector/inspector_gui.py:17, built with none ateditor_widget.py:151andbuild_tab_tools_menu.py:103; no code sets.namespace), on je_editor 1.0.27. The README no longer lists it among the editor's features; the Sphinx pages say it is empty. Needs JEditor to feed it from somewhere (the IPython console's namespace, or a paused debugger's), or to drop it. - #118 [BLOCKED] A settings file whose
ui_styleis not a string stops the IDE from starting:EditorMain.__init__callsstartup_setting()unguarded (je_editor/pyside_ui/main_ui/main_editor.py:245), which hands the value to qt_material'sapply_stylesheet, and a number raisesTypeErrorinside the window's constructor, before PyBreeze can do anything (reproduced on je_editor 1.0.27 with{"ui_style": 42}in.jeditor/user_setting.json: the window was never built). A theme name that does not exist only logs a warning. Needs JEditor to check the saved style's type, or to guard that call as_restore_open_files_sessionis guarded. - #119 [BLOCKED] Most of the IDE's start is JEditor importing two tools nobody has opened yet:
build_dock_menu.py:17,22andbuild_tab_tools_menu.py:9-10(je_editor/pyside_ui/main_ui/menu/) importChatUI, which bringslangchain_openaiandopenai(2.0–2.5 s), andIpythonWidget, which brings IPython (about 1 s), at the top. With-X importtimeon je_editor 1.0.27,build_dock_menuis 3.1–3.7 s of the 4.1–4.9 s it takes to import PyBreeze's main-window module. PyBreeze imports its own heavy GUIs (the automation packages', SSH) when they are first opened. Needs JEditor to import these two in the actions that open them. - #120 [BLOCKED] A locust script run with JEditor's Run Program, Run Debugger or shell runs its HttpUser users one at a time: those start their process with the IDE's own environment (
subprocess.Popenwith noenv,je_editor/pyside_ui/code/code_process/code_exec.py:99,194,.../shell_process/shell_exec.py:95), which carriesLOCUST_SKIP_MONKEY_PATCH(PyBreeze sets it so that locust cannot patch the IDE with gevent), and unpatched a 3 s test of 10 users took over three minutes. PyBreeze's own runs (the automation menus, Run with..., installs, the JupyterLab server) leave it out throughchild_environment(), which drops every variable whose value issubprocess_util.IDE_ONLY. Needs JEditor to let its host give the environment for the processes it starts, or to drop variables with that value. - #121 [BLOCKED] PyBreeze cannot be installed on Python 3.15 (due October 2026):
requirements.txt,pyproject.tomlanddev.tomlpinPySide6==6.11.2, whose wheels sayRequires-Python <3.15(with 3.15.0rc2, pip finds no PySide6 to install). PySide'sdevbranch raised the bound to<3.16on 2026-08-25 for its next release, and three days later moved QtWebEngine out ofPySide6into a wheel of its own,PySide6_WebEngine(PySide6is then Essentials and Addons only;create_wheels.py). Moving the pin to that release therefore also needsPySide6_WebEnginebeside it, in all three files: JEditor importsQtWebEngineWidgetsas the IDE starts (its browser) and the JupyterLab tab is aQWebEngineView. je-editor and frontengine pinPySide6==6.11.2as well and move with it (workspace). Then add 3.15 to the CI matrix, the classifiers and the README's version range. Blocked until that PySide6 release, andPySide6_WebEngine, are on PyPI.