Skip to content

CLI: Update SDK to 9ac854e2d73931cce7e4879b8505b1e11cf1e27c and add new commands/flags - #292

Open
kernel-internal[bot] wants to merge 6 commits into
mainfrom
cli-coverage-update
Open

kernel-internal[bot] wants to merge 6 commits into
mainfrom
cli-coverage-update

Conversation

@kernel-internal

@kernel-internal kernel-internal Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

This PR updates the Go SDK to 9ac854e2d73931cce7e4879b8505b1e11cf1e27c and adds CLI commands/flags for new SDK methods.

SDK Update

  • Updated kernel-go-sdk to 9ac854e2d73931cce7e4879b8505b1e11cf1e27c. This branch also has the earlier bumps to 3c8b90c8bea096937d6cee06eabd6076e1801376, 6d9c6187b9e9ddbe1a1546a48b1544dacbb62417 and 64c58f83184c4ea19b63938eb496b86b2ff93a5f (v0.123.0).

Coverage Analysis

This PR was generated by performing a full enumeration of SDK methods and CLI commands. Every SDK method in api.md is reachable from the CLI, except the x-cli-skip Config Registry endpoints. browsers curl and search reach their endpoints over raw HTTP rather than through the typed SDK methods, as before.

SDK changes covered:

  • 3c8b90c: browser pools support egress allowlists (network.allowed_hosts).
  • 6d9c618: the telemetry SSE stream can filter by event type (BrowserTelemetryStreamParams.Type).
  • 64c58f8: release v0.123.0. Only release metadata changed, so no new coverage.
  • 9ac854e: Kernel Visa transaction reporting. Adds the confirm_transaction vault item operation (ConfirmTransactionVaultItemOperationRequestParam) and merchant_category / merchant_category_code on KernelCardVaultItemSpecParam.

These were intentionally not added:

  • Telemetry.Export and Telemetry.Storage on BrowserPoolNew/Update/AcquireParams, and Telemetry.Export on BrowserUpdateParams. The API rejects export and storage on pools and silently ignores export on PATCH /browsers.
  • AuditLogExportChunkParams.Limit is still not exposed. It was already missing before this SDK change, and audit-logs download manages chunk paging itself.
  • Deprecated fields (ProxyID, DisableDefaultProxy, the managed-auth Proxy and BrowserTelemetry) are still covered by the newer flags that replaced them.

New Commands

  • kernel vaults items invoke <vault> <key> confirm_transaction --params|--spec-file for client.Vaults.Items.PerformOperation() with OfConfirmTransaction. It requires status, transaction_type, amount, currency and occurred_at. The CLI checks the enums, that amount is a non-negative integer and that occurred_at is an ISO 8601 timestamp, and it rejects unknown keys. Before this change, invoking confirm_transaction fell through to the parameterless path and sent an invalid body.

New Flags

  • kernel browser-pools create --allowed-host for BrowserPoolNewParams.Network.AllowedHosts
  • kernel browser-pools update --allowed-host / --clear-allowed-hosts for BrowserPoolUpdateParams.Network.AllowedHosts
  • kernel browsers telemetry stream --types now sends BrowserTelemetryStreamParams.Type to the API (server-side filter).
  • kernel vaults cards create --provider kernel --spec documents merchant_category and merchant_category_code for KernelCardVaultItemSpecParam.MerchantCategory/MerchantCategoryCode. The spec is raw JSON that is passed through as-is, and both fields now appear in vault item output.

Other changes

  • kernel browser-pools get shows an Allowed Hosts row. The help text and README for allowlists on pooled browsers are updated.
  • browsers create --private-host without --allowed-host no longer sends "allowed_hosts": [].
  • An empty --allowed-host is rejected.

Testing

  • go test ./... passes. New unit tests cover pool allowlists, stream types, the confirm_transaction request body and its param validation.
  • Live API smoke tests:
    • Earlier commits: pool allowlist create/update/clear, leased-browser allowlist update and telemetry --types filtering.
    • This commit: creating a Kernel card with merchant_category/merchant_category_code reached server validation. The server stopped it with "wallet is pending_authorization", because enrolling a Kernel wallet needs a cardholder passkey, so the full card flow could not be run.
    • confirm_transaction: checked the missing-params and invalid-status errors and the available_operations check against a live item.
    • All test resources were cleaned up.

Triggered by: kernel/kernel-go-sdk@9ac854e
Reviewer: @kernel-internal[bot]

🤖 Generated with Claude Code

…ew commands/flags

- Bump kernel-go-sdk to 3c8b90c8bea096937d6cee06eabd6076e1801376
- browser-pools create: add --allowed-host (BrowserPoolNewParams.Network.AllowedHosts)
- browser-pools update: add --allowed-host / --clear-allowed-hosts
  (BrowserPoolUpdateParams.Network.AllowedHosts); clear flags preserve the
  other network flags passed in the same command
- browser-pools get: show Allowed Hosts
- browsers update/create: refresh help now that leased pooled browsers
  support allowlist changes; --pool-* + --allowed-host now points users at
  the pool flags
- Fix: browsers create --private-host/--proxy-route without --allowed-host
  no longer sends an invalid empty "allowed_hosts": [] list

Tested against the live API: browser-pools create --allowed-host,
browser-pools get (Allowed Hosts row), browser-pools update --allowed-host
--private-host, update --clear-allowed-hosts --private-host (kept private
hosts), empty --allowed-host rejected, browser-pools acquire + browsers
update --allowed-host on a leased browser + release, browsers create
--private-host (no allowed_hosts sent). Resources cleaned up.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@socket-security

socket-security Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang/​github.com/​kernel/​kernel-go-sdk@​v0.122.1-0.20261009181557-f737b63ffd16 ⏵ v0.123.1-0.20261010230324-9ac854e2d73973 +1100100100100

View full report

…r telemetry stream by type server-side

- Bump kernel-go-sdk to 6d9c6187b9e9ddbe1a1546a48b1544dacbb62417
- `kernel browsers telemetry stream --types` now sends
  BrowserTelemetryStreamParams.Type so the API filters events server-side
  (client-side filtering is kept as a fallback)

Tested: browsers telemetry stream <id> --replay all --types cdp_command,api_call
(only matching events delivered; server sends id-only frames for skipped
events, which the SDK decoder ignores); unfiltered stream for comparison;
go test ./...

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to 3c8b90c8bea096937d6cee06eabd6076e1801376 and add new commands/flags CLI: Update SDK to 6d9c6187b9e9ddbe1a1546a48b1544dacbb62417 and add new commands/flags Oct 9, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want higher recall? High effort reviews run extra passes and find more bugs. A team admin can switch effort levels in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f44e578. Configure here.

Comment thread cmd/browsers_telemetry.go
Bumps kernel-go-sdk to v0.123.0 (64c58f83184c). The SDK change since the
previous version is release metadata only; full enumeration of api.md
methods vs CLI commands found no new coverage gaps (config-registry
endpoints are x-cli-skip).

Tested: go build ./... (no new commands/flags to smoke test)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to 6d9c6187b9e9ddbe1a1546a48b1544dacbb62417 and add new commands/flags CLI: Update SDK to 64c58f83184c4ea19b63938eb496b86b2ff93a5f and add new commands/flags Oct 9, 2026
meliaj and others added 3 commits October 9, 2026 22:32
An --allowed-host whose entries were all blank was dropped, so a browser
or pool was created with unfiltered egress. Fail instead on create and
update. Document that other pool network flags replace the whole network
config and remove an existing allowlist, and stop sending an empty
proxy_routes list on browser create.
…onfirm_transaction

- Bump kernel-go-sdk to 9ac854e2d73931cce7e4879b8505b1e11cf1e27c
- vaults items invoke <vault> <key> confirm_transaction --params/--spec-file
  for ConfirmTransactionVaultItemOperationRequestParam (status,
  transaction_type, amount, currency, occurred_at), validated client-side
- Document merchant_category / merchant_category_code on KernelCardSpec and
  include them in vault item output

Tested: go test ./...; against the live API, kernel cards create with
merchant_category fields reached server validation (rejected because the
Kernel wallet was not enrolled, which needs a cardholder passkey);
confirm_transaction param validation and the advertised-operation check.
Test vault cleaned up.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to 64c58f83184c4ea19b63938eb496b86b2ff93a5f and add new commands/flags CLI: Update SDK to 9ac854e2d73931cce7e4879b8505b1e11cf1e27c and add new commands/flags Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants