snuziale
90d · built 2026-09-08
Performance
What snuziale shipped in the selected window, measured in ETV, and how it compares with the 90 days before it.
Effective capacity
−0.2engineers
delivers like 0.8 (0.8x pre-AI)
Output (ETV)
10.2ETV
+1131.3% vs 0.8 prior
Features share
29.4%
+1.7 pp vs prior window
Fixes share
11.3%
−0.7 pp vs prior window
Work mix
29.4% Features13.5% Maintenance40.2% Tests5.7% Docs11.3% Fixes
11 commits over 90 days, ending 2026-09-08.
Daily performance
Daily ETV, stacked by Features, Maintenance, Tests, Docs and Fixes.
Repository spread
Where this developer's commits land. Concentrated work (top1 > 80%) vs polymath spread (top1 < 30%).
Most impactful commits
Top 10 by ETV in the last 90 days.
- 3.9ETVfix(apollo-wind): quality pass across the component library A single change covering the apollo-wind audit: exports, test coverage, accessibility, design tokens, API consistency and dependency hygiene. Coverage gate: - vitest only enforces limits nested under coverage.thresholds, so the previous top-level keys were silently ignored and the gate never ran; nest them with a ratcheting floor (lines 60, functions 63, branches 54, statements 58) and exclude the Storybook-only src/templates demos from the metric - raise testTimeout and hookTimeout to 20s so wall-clock variance on shared CI runners cannot fail correct tests - new suites for src/components/custom (14 components), the untested ui components (chart, drawer, editable-cell, button-group, command, datetime-picker), the layout row/column/grid primitives, and form-designer, form-plugins, form-state-viewer and schema-viewer, each file including a jest-axe check Exports: - chart and drawer were implemented but unreachable from both the ui barrel and the package root; add them along with portal-container, lockable-value-field and variable-picker - give src/foundation an index barrel; the ./foundation subpath is held back for now, because the token surface is not ready for consumption Accessibility: - name the icon-only controls that had tooltip-only labels: panel-flow rail nav, form-designer section and field move/delete buttons, the section accordion chevron, the Always required checkbox and the rule-builder selects - associate the field-renderer and flow-properties-simple select triggers with their field labels Tokens and consistency: - unify the dialog, alert-dialog, sheet and drawer overlays on the theme-aware bg-curtain scrim token, whose alpha is restored in the preceding apollo-core commit - stats-card moves its per-render variant map into cva variants; avatar gains a cva size variant - forward refs from combobox, date-picker, date-range-picker, datetime-picker, file-upload and tree-view - adopt the shadcn v4 data-slot convention across all ~70 ui components, which also fixes calendar selectors that never matched Dependencies: - de-duplicate tailwindcss, @tailwindcss/postcss and autoprefixer, each of which was declared in both dependencies and devDependencies; all three stay in dependencies, because dist/tailwind.css ships a bare `@import "tailwindcss"` that Tailwind resolves from the installed package's own directory, and postcss.config.export.js imports the other two at consumer runtime. Installing @uipath/apollo-wind alone must be sufficient, so tailwindcss is a dependency and not a peer. Cleanup: - fix the biome templates exclusion, which never matched src/templates - delete the empty src/components/UiPath directory; the deprecated fontFamily.sans alias is kept a while longer for existing templates Storybook: - stories added for previously undocumented ui and custom components - derive the component gallery's story-ID prefix from the gallery's own story ID, so its links resolve both standalone and composed - drop the quick start's `npx shadcn@latest add` step Claude-Session: https://claude.ai/code/session_015n5YBa3rwBSxCUjkGNRKbG Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>github.com-UiPath-apollo-ui · f4f880f2 · 2026-08-25
- 2.7ETVfeat(apollo-react): add unified CanvasEdge with waypoint editing and pluggable routing Introduce CanvasEdge, a single canvas edge component whose behaviors compose via data flags (enableEditing, enableExecution, enableToolbar), and refactor SequenceEdge into a thin backward-compatible preset (routing: 'handle' + execution + toolbar). - Orthogonal waypoint routing with draggable segments, insert/remove waypoints, grid snapping, and node-drag rebalancing - Shared primitives (EdgePath, EdgeArrow, EdgeLabel, handles) and hooks extracted from the old SequenceEdge monolith - Pluggable EdgeRouter contract with useGraphRouter orchestration (fingerprint-based store subscription; manual waypoints win) - Support React Flow's animated edge flag (no dasharray override) - Stories: editing, handle routing, controlled mode, pluggable router, and execution states; unit tests for geometry and waypoint math Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>github.com-UiPath-apollo-ui · 106d268b · 2026-06-11
- 1.6ETVfeat(apollo-react): add line jumps to crossing canvas edges Waypoint-routed edges can now hop over the edges they cross, so criss-crossing lines read as passing over rather than joining. Opt in per edge with `data.enableLineJumps`. Edges publish their polylines to a shared `EdgeCrossingsStore`, which derives every crossing once per commit and hands each edge back only its own jumps. At a crossing it is the horizontal segment that arcs, which keeps the notch pattern stable while nodes are dragged. Jumps are derived from the vertices and only ever change the path string, so publishing cannot re-trigger the computation that produced it. A crossing counts only where it clears both segments' ends, so a T-junction or a shared handle reads as a junction rather than a crossing. The clearance widens to the border radius at a bend, where the rendered line curves off the ideal corner and an arc would sit beside the stroke rather than over it. `createRoundedPath` grows an optional `jumps` argument that replaces a stretch of a straight run with a semicircular arc. Jumps that would eat into a rounded corner, or that sit closer together than one arc width, are dropped so a densely crossed stretch degrades to fewer notches instead of a scalloped line. A registration that repeats positions the store already holds is dropped. That is what a re-render hands over while a drag rebuilds its waypoints, and without the guard every notification would schedule a second whole-graph pass that could only reproduce the jumps it just published. `EdgePath`, `EdgeArrow` and `EdgeLabel` are memoized so an edge notified about a crossing elsewhere on its path does not reconcile its arrow and label as well. `EdgeCrossingsProvider` defers to an ancestor store, so mounting one over a `BaseCanvas` cannot split a canvas across two registries. The story is built as a documentation page rather than a bare canvas, since the rules are subtle enough that a caption did not explain them: an annotated diagram of a single jump, cards for the interiority rule and for the guards that suppress an arc, and a rule table covering all eight outcomes including the mixed opt-in case. That page rests on shared chrome extracted from BaseNode's Shapes and Execution States stories, which had each grown a private copy of it: - StoryPage: themed root, title and lede, plus StorySection and StoryCollapsibleSection for the blocks below the preview - StoryPreview: framed 90vw canvas with an expand overlay. The children are live in one branch at a time, so toggling remounts the canvas - StorySpecTable: generic over the row type, with per-column cell variants Waypoint routing only: handle-routed edges produce a path string with no vertices to intersect. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01C3Toj3SHbt75zwJ9ufqojSgithub.com-UiPath-apollo-ui · 1e553a23 · 2026-08-10
- 0.6ETVperf(apollo-wind): re-render only the edited field in MetadataForm The top-level watch() re-rendered the whole form on every keystroke, rebuilding the Zod schema and the form context and re-rendering every section and field. Values now flow through a ref fed by a single subscription, the schema reference is stabilized by deep equality, and the sub-components are memoized. Typing re-renders nothing but the edited field's Controller. Anything memoized behind that stable context has to subscribe to what it reads. Each layout subscribes via useWatch to the fields its section and step `conditions` reference, and FormActions subscribes to isSubmitting and to its action `conditions` so the submit button still disables and conditional actions still appear. Also seeds defaultValues from initialData, clears a select's options when they go away rather than keeping a stale list, passes dot-path field values to plugin hooks via get() instead of a bare index, and replaces FormStateViewer's watch() call, which set watchAll on the shared control and re-rendered the useForm owner once per keystroke. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>github.com-UiPath-apollo-ui · e46a6f55 · 2026-09-04
- 0.5ETVfix(apollo-react): eliminate unnecessary re-renders in StageNode canvas components Fixes the re-render storms visible in react-scan when interacting with stage nodes: - DraggableTask: gate the zoom store subscription on an active drag transform — the selector resolves a constant while idle, so canvas zoom changes no longer re-render every task, while an active drag still tracks zoom reactively - StageTaskDragOverlay: same drag-gated zoom selector so idle overlays stay quiet - StageNode: mount the add/replace-task FloatingCanvasPanels only while open, with stable onClose handlers (closed panels subscribed to node internals and re-rendered every drag frame) - useFloatingPosition: subscribe to useInternalNode only while open, fixing the same leak for all FloatingCanvasPanel consumers - Task context menus: unify on a single task-keyed contract (getContextMenuItems(task)) shared as one stable reference across all task items — per-task inline closures were defeating the memo on every DraggableTask/EventDrivenTaskItem/AdhocTaskItem, re-rendering all tasks on every parent render (worst: per pointermove during task drag) - StageEdge: memoize the detached-SVG arrow measurement (getTotalLength/getPointAtLength) by path string - StageNodeWrapper (stories): use areNodePropsEqualIgnoringPosition and hoist menuItems so node drags don't re-render the whole stage per frame Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>github.com-UiPath-apollo-ui · bdd13d38 · 2026-06-11
- 0.4ETVfix(apollo-react): keep gallery story links resolvable and theme-aware The canvas and material gallery cards linked to hardcoded story IDs and navigated the top frame directly, which broke in two ways. Story IDs carry the composing Storybook's `titlePrefix` (for example `apollo-react-canvas-`) in apps/storybook, but are unprefixed when this package's own Storybook runs standalone, so a hardcoded ID resolved in only one of the two. Derive the prefix from the gallery story's own ID instead, which is correct in both. Storybook also keeps globals such as theme and locale in the URL only. Because the cards do a full top-frame navigation, any global not carried across was dropped on click. Rebuild the target URL from the current top-frame query string, replacing only `path`, falling back to a bare path when the top frame is cross-origin. Also allows a gallery entry to omit storyPath, for components that have no story of their own. Claude-Session: https://claude.ai/code/session_015n5YBa3rwBSxCUjkGNRKbG Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>github.com-UiPath-apollo-ui · 0d534749 · 2026-08-25
- 0.3ETVfix(apollo-react): route edges from real handle anchors useGraphRouter built its route request from node bounding boxes: always the right-edge midpoint for a source and the left-edge midpoint for a target, and always node.position, which xyflow stores parent-relative for a child node. Multi-handle nodes were routed from a point no handle occupies, vertical flows were told Right/Left regardless of the face the edge leaves, and every child of a container entered the request short by the container's own position, so its route was computed in the wrong coordinate frame. RouteAnchor already documented its coordinates as absolute. Anchors now come from xyflow's own getEdgePosition, so the router plans from the same points the renderer draws from, and node boxes use internals.positionAbsolute. Before handles are measured, anchors fall back to the previous node-box faces. resolveRouteAnchors and toRouteNode are exported for hosts running their own layout engine outside the hook. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>github.com-UiPath-apollo-ui · 1c00b999 · 2026-08-13
- 0.2ETVfeat(apollo-react): persist edge routing Canvas shipped interactive edge routing but no way to store a route: nodeSchema gives nodes a required, open-ended ui slot, while edgeSchema had none and, in zod's default strip mode, silently discarded one. A host saving a graph had to fork the schema and reimplement Apollo's geometry helpers from the outside. - edgeSchema gains an optional ui slot (waypoints, routedWaypoints, autoRouted) with a catchall, so host keys and keys from a newer client survive a parse. An explicit null normalises to absent rather than failing the whole parse. - The pure route helpers are exported: rebalanceWaypoints, waypointsEqual, waypointsPositionallyEqual, moveWaypoint, generateWaypointId, calculateAutoWaypoints, snapPointToGrid. rebalanceWaypoints keeps a route attached when the endpoints move by different deltas, which is what a host otherwise has to give up on when applying layout, paste or subflow moves. - CanvasEdgeData gains an explicit autoRouted flag. Node-face clearance was keyed entirely off which field the route arrived in, so unifying the two fields, a plausible refactor once both persist, silently dropped it. The default keeps the existing inference. - Documented the auto-route turn convention on calculateAutoWaypoints and routedWaypoints, so a host layout engine can agree with the renderer's fallback instead of reverse-engineering it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>github.com-UiPath-apollo-ui · ce1101dc · 2026-08-13
- 0.0ETVfix(apollo-react): clear all pnpm audit findings across prod and dev deps Takes `pnpm audit` from 21 findings to zero, exiting 0 for both production and dev dependencies. Previously: 8 prod (2 high, 5 moderate, 1 low) and 13 dev-only (3 high, 10 moderate). Production dependencies ----------------------- mermaid 11.15.0 -> 11.16.1, a direct dependency of apollo-react GHSA-6x64-9x62-f2gx moderate CSS injection into diagram siblings GHSA-3rrr-jr9j-h3q3 moderate architecture prototype pollution GHSA-2v8p-3f2j-5mp7 moderate XY chart infinite-loop DoS GHSA-rhh3-jpg6-66xh moderate radar diagram DoS GHSA-c4c3-pg64-4m4v low config API prototype pollution Bumped in the manifest rather than pinned via the lockfile alone, so published consumers of apollo-react also require the patched line. This is the only published manifest that changes. postcss 8.5.19 -> 8.5.23, via the existing workspace override GHSA-fxqj-rqcc-2cmp moderate incomplete fix of GHSA-6g55-p6wh-862q; attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset Reaches apollo-wind (via @tailwindcss/postcss and autoprefixer, plus a direct devDependency) and apollo-core. Targets 8.5.23, the minimum patched version: 8.5.24-8.5.26 are still quarantined and carry unrelated BOM/list.split changes, and 8.5.26 additionally bumps nanoid. socket.io-parser 4.2.6 -> 4.2.7, apollo-vertex only GHSA-2m8v-j782-fhvr high zero-attachment memory exhaustion brace-expansion 5.0.8 -> 5.0.9, apps and dev toolchain GHSA-rgw5-rvv9-x895 high DoS via unbounded intermediate arrays, bypassing the mitigation 5.0.8 shipped for CVE-2026-14257 Dev-only dependencies --------------------- None of these ships in a published package, which is why the earlier `--prod` audits looked clean. undici 6.27.0 -> 6.28.0 and 7.28.0 -> 7.29.0 GHSA-4cwx-7wf7-3272 high cross-user information disclosure GHSA-8xcm-r25x-g524 moderate downstream response desynchronization GHSA-m8rv-5g2x-5cg5 moderate CRLF injection via blob-like body type GHSA-jr45-8vmc-qm54 moderate cross-user information disclosure GHSA-v3r7-h72x-cjcm moderate cookie attribute injection Both majors are legitimately live and were patched separately, so each got its own version-bounded pin: 6.x via @actions/http-client > @actions/core > @semantic-release/npm, 7.x via @semantic-release/github. fast-uri 3.1.4 -> 3.1.5, via ajv (commitlint and the MCP sdk) GHSA-7p8r-x3mc-p8w7 high host confusion via backslash ip-address 10.2.0 -> 10.3.1, via express-rate-limit > MCP sdk > shadcn GHSA-mwp4-54f8-5fhr high Address4 decodes leading-zero octets as decimal rather than rejecting them GHSA-4xrf-jv44-h6hh moderate CIDR suffix suppresses validation GHSA-22jq-vg5j-6vgg moderate IPv4-mapped/NAT64 misclassification hono 4.12.28 -> 4.12.34, via MCP sdk > shadcn GHSA-8j4g-w8fx-2239 moderate ReDoS in CORS middleware Method ------ Every parent ranges on a caret or tilde that already admits its fix, so each transitive used the surgical add/install/remove/install pattern and the `overrides:` block is unchanged except for the two entries that were already there (postcss and hono, bumped in place). Every second install reported "Already up to date", confirming the lockfile pins hold with no permanent override added. Bumping apollo-react's mermaid alone was not sufficient: nextra > @theguild/remark-mermaid ranges on ^11.0.0 and kept its existing pin, leaving mermaid duplicated at 11.15.0 and 11.16.1 with the vulnerable copy live in apollo-docs and apollo-vertex. Collapsed to a single 11.16.1, net -6 packages. Seven of the eight fix versions are inside the 14-day quarantine, so each gets a version-scoped minimumReleaseAgeExclude entry; brace-expansion retargets its existing 5.0.8 entry rather than adding one. socket.io-parser needed none at 22 days old. Override ranges are deliberately major-bounded: undici's latest is 8.10.0 and fast-uri's is 4.1.2, so open `>=` ranges would have jumped a major. The newer in-range releases that do exist (ip-address 10.4.0, hono 4.13.0) are themselves still quarantined, so resolution lands on the vetted version every time. Supply-chain vetting, 2026-08-06 -------------------------------- All six checks completed for all eight package versions. Ten of the thirteen newly-resolved packages carry SLSA provenance via GitHub OIDC trusted publishing. Publisher identity was compared against the previous version in every case, dependency sets were diffed old-to-new, and the upstream diff was read and confirmed to match each advisory. Three items warrant explicit note: ip-address publisher changed from beaugunderson to GitHub OIDC at 10.2.1. Cleared: the switch is explained by an in-repo commit "Switch release workflow to npm trusted publishing (OIDC)" in the same diff, holds through 10.4.0, beaugunderson remains sole maintainer, and the attestation points at the repo that maintainer owns. A hardening change, not a takeover. fast-uri no provenance, and never has had any (verified across 3.1.2-4.1.2) with an unchanged publisher, so its absence is not a regression. Same for brace-expansion and @braintree/sanitize-url. For these three the published tarball file lists were inspected instead: expected layout, no unexpected binaries or scripts. install hooks none of the thirteen newly-resolved packages declares an install, preinstall or postinstall script, and the allowBuilds allowlist is untouched, so pnpm's default build-script blocking remains fully in force. Forced transitives, vetted the same day: nanoid 3.3.12 -> 3.3.16 (required by postcss 8.5.23), @mermaid-js/parser 1.1.1 -> 1.2.0, cytoscape 3.33.1 -> 3.34.0, @braintree/sanitize-url 7.1.1 -> 7.1.2. All are well past the quarantine. Verification ------------ pnpm audit exit 0, no known vulnerabilities pnpm audit --prod exit 0 pnpm check:dependencies exit 0 apollo-react tests 2333 passed / 138 files apollo-wind tests 1072 passed / 62 files builds apollo-core (postcss CLI), apollo-wind and apollo-react all clean commitlint accepts valid, rejects invalid (the ajv > fast-uri consumer) semantic-release --dry-run loads every plugin (the undici consumer) mermaidAPI.getDiagramFromText, which canvas/utils/coded-agents/ mermaid-parser.ts calls through `as any`, is still present in 11.16.1. The newly deprecated mermaidAPI.setConfig() is unused here, and the architecture service-ordering change does not apply since that parser only handles flowcharts. Two pre-existing issues were found while testing and deliberately left alone, both already present on main and unrelated to these bumps: apollo-wind's code-block.tsx imports react-syntax-highlighter without declaring it, resolving only by hoisting luck; and several apollo-react locale catalogs have the ICU keyword `other` itself translated (`autre`, `기타`), so lingui compile falls back for 3 messages per locale. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>github.com-UiPath-apollo-ui · cefd8df5 · 2026-08-07
- 0.0ETVfix(apollo-core): restore the curtain token's alpha channel The curtain scrim was authored in Sass syntax (`rgba(black, 0.3)`), which the token pipeline cannot read. Style Dictionary's `color/css` transform parses values with tinycolor2, and tinycolor cannot parse a color keyword inside `rgba()`. On failure it does not throw: it returns an invalid color initialized to r=0, g=0, b=0, a=1. Because getAlpha() then reports 1, the transform takes its toHexString() branch and the alpha is discarded, emitting an opaque `#000000` into every generated output (css/theme-variables.css, css/variables.css, scss/_variables.scss, scss/theme.scss). The fallback happens to be black, so a broken token still looked like a plausible curtain colour. Re-author the six values as 8-digit hex, matching how every other alpha-bearing token in this file is expressed (see backgroundHover's `{color.ink.550.value}14`). tinycolor parses these, getAlpha() returns the real alpha, and the transform emits rgba() with the designed opacities preserved: 0.3 light, 0.5 light-hc, 0.75 dark / dark-hc / future-dark, 0.3 future-light. curtain was the only token in the set authored as a literal rgba(), and the only one whose value the color transform therefore touched. It also had no consumers until apollo-wind adopted `bg-curtain` for the dialog, alert-dialog, sheet and drawer overlays, which is what surfaced it. Claude-Session: https://claude.ai/code/session_015n5YBa3rwBSxCUjkGNRKbG Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>github.com-UiPath-apollo-ui · 1ba2948b · 2026-08-25