chore(whatsapp): bump local-whatsapp pin to 0.3.1 for the reply nudge - #827
defangdevs wants to merge 1 commit into
Conversation
A WhatsApp sender only sees WhatsApp, so a Codex turn that runs long leaves their message unanswered for 15+ minutes with no sign of life. local-channels#79 (local-whatsapp 0.3.1) appends a short instruction to every delivered message asking the agent to acknowledge at once and post progress updates; this box only gets it once the pin moves. Bump REV in modules/src/whatsapp-cli.py to the #79 merge commit 7d0d307 and refresh the four per-file sha256 values (same file set as 0.3.0). Regenerated modules/agent-box.nix and the golden agent-box-whatsapp payload. Verification: nix run .#assemble, nix run .#update-golden; python3 tests/test-whatsapp-cli.py (11 OK); nix checks whatsapp-cli, module-generated-up-to-date, golden-snapshot, vendor-integrity, source-tree. Co-Authored-By: Claude Code <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RZBL8MqNXVVnRmxR5DK5rU
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe WhatsApp runtime revision and SHA-256 hashes for four files were updated in the runtime configuration, download script, and golden test payload. ChangesWhatsApp runtime pin
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to The updated WhatsApp runtime pin appears ready to merge after normal checks; no actionable issue remains in the supplied evidence. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The update preserves the existing download checks, pairing gate, and separation between runtime files and linked-device state. No introduced security weakness was established. However, the new upstream code and its instruction behavior were not independently inspected, so unchanged permissions and trust behavior cannot be fully confirmed. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
@coderabbitai review |
|
|
@coderabbitai review |
✅ Action performedReview finished.
|



Problem
A WhatsApp sender only sees WhatsApp, so a Codex turn that runs long leaves their message unanswered for 15+ minutes with no sign of life. defangdevs/local-channels#79 (local-whatsapp 0.3.1) appends a short instruction to every delivered message asking the agent to acknowledge at once and post progress updates. The box only gets it once the pin moves.
Change
modules/src/whatsapp-cli.py:REV->7d0d307(the deploy-test: dispatch inputs for password shape, Spot, and SSM diagnostics #79 merge commit, taglocal-whatsapp-v0.3.1) and refreshed sha256 for the same four files as 0.3.0.modules/agent-box.nixand the goldenagent-box-whatsapppayload.Nothing else changes: the pinned file set, install flow and integrity checks are untouched. The Claude peer (
peer.mjs) comes from the plugin marketplace, not this pin.Verification
nix run .#assemble,nix run .#update-goldenpython3 tests/test-whatsapp-cli.py: 11 OKwhatsapp-cli,module-generated-up-to-date,golden-snapshot,vendor-integrity,source-tree🤖 Generated with Claude Code
https://claude.ai/code/session_01RZBL8MqNXVVnRmxR5DK5rU