Skip to content

CLI: Update SDK to f737b63ffd168cc67bf0158b961ca3275c94bd1c and add new commands/flags - #291

Merged
yummybomb merged 4 commits into
mainfrom
cli-coverage-update
Oct 9, 2026
Merged

yummybomb merged 4 commits into
mainfrom
cli-coverage-update

Conversation

@kernel-internal

@kernel-internal kernel-internal Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

This PR updates the Go SDK to f737b63ffd168cc67bf0158b961ca3275c94bd1c and adds CLI commands/flags for new SDK methods.

SDK Update

  • Updated kernel-go-sdk to f737b63ffd168cc67bf0158b961ca3275c94bd1c (v0.122.1-0.20261009181557-f737b63ffd16)
  • The latest SDK commit (f737b63) only changes documentation for the 1Password fill result: fill_unknown can now carry error_code: autosubmitFailed, and after an uncertain fill the caller should inspect the page. The CLI already prints error_code for every 1pw_fill status, and its help text already gives this guidance, so no code changes were needed for it.
  • An earlier commit on this branch updated the SDK to 6f3ae15351013fd71e5d554b69d7e532e1e592db, which adds video_memory for the 4GiB VRAM GPU browser tier.

Coverage Analysis

This PR was generated by performing a full enumeration of SDK methods and CLI commands. After this PR, every method in api.md has a CLI command. The only exception is ConfigRegistry.*, which is skipped because those endpoints are marked x-cli-skip.

New Commands

  • kernel vaults get-encryption-key <vault> for client.Vaults.GetEncryptionKey(). It shows a table by default, and -o json returns the raw key response.

New Flags

  • --video-memory on kernel browsers create for BrowserNewParams.VideoMemory. It accepts 2GiB (the default: 4 vCPU, 6GiB memory) or 4GiB (8 vCPU, 12GiB memory), matched case-insensitively and checked before the request is sent. It requires --gpu. browsers get and create now show a "Video Memory" row when the API returns one.
  • The new encrypted_value field (CredentialVaultFieldInputParam.EncryptedValue, CredentialVaultFieldUpdateParam.EncryptedValue) goes through the existing --spec-file JSON on vaults credentials create/update. The help text and README now describe it.

Testing

  • f737b63 bump: go build ./..., go vet ./... and go test ./... all pass.
  • browsers create --gpu --video-memory 2GiB -t 30: the session was created, and browsers get showed GPU true, Memory 6GiB, Video Memory 2GiB. The test browser was deleted afterwards.
  • browsers create --gpu --video-memory 4GiB: the API received the 4GiB tier but returned No_gpu_browsers_available (at capacity), so no 4GiB session was created.
  • --video-memory 3GiB is rejected on the client with a clear error. A new unit test, TestBrowsersCreate_WithVideoMemory, covers this.
  • vaults get-encryption-key: table output, -o json output, and the not-found error all checked.
  • Created a credential with a real ECDH-ES/A256GCM JWE encrypted_value. The item became ready, and the update bumped the version from 1 to 2.

Triggered by: kernel/kernel-go-sdk@f737b63
Reviewer: @kernel-internal[bot]

🤖 Generated with Claude Code


Note

Low Risk
Mostly new CLI flags/commands and docs atop the SDK; credential encryption still flows through existing spec-file JSON without new local crypto logic.

Overview
Updates kernel-go-sdk and exposes two new API surfaces in the CLI.

Adds kernel vaults get-encryption-key so custom credential-collection apps can fetch a vault’s public JWK (kid, ECDH-ES / A256GCM) for browser-side JWE encryption, with table or -o json output. README and vaults credentials help now document encrypted_value as an alternative to value on create/update specs (mutually exclusive).

Adds --video-memory on kernel browsers create (2GiB / 4GiB, case-insensitive client validation; omitted leaves the API default). Create passes it through to BrowserNewParams, and browsers get/create detail show Video Memory when present. TestBrowsersCreate_WithVideoMemory covers mapping, omission, and invalid sizes.

Reviewed by Cursor Bugbot for commit 456553a. Bugbot is set up for automated code reviews on this repo. Configure here.

- Bump github.com/kernel/kernel-go-sdk to c203c7e5a0c9781bcaf1056cb7665fd670867c4b
- Add `kernel vaults get-encryption-key <vault>` for client.Vaults.GetEncryptionKey
- Document encrypted_value (CredentialVaultFieldInputParam/UpdateParam.EncryptedValue)
  in credentials create/update help; it passes through --spec-file JSON

Tested: vaults get-encryption-key (table, -o json, not-found error);
credentials create and update with a real ECDH-ES/A256GCM encrypted_value
(item ready, version bumped); vault cleaned up. go test ./cmd passes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@socket-security

socket-security Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang/​github.com/​kernel/​kernel-go-sdk@​v0.121.1-0.20261009121157-454206ab83bc ⏵ v0.122.1-0.20261009181557-f737b63ffd1673 +1100100100100

View full report

…2.0)

SDK change is a release version bump only (no API changes); full
enumeration of api.md methods against CLI commands found no new gaps.

Tested: go build ./..., go test ./cmd/...

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to c203c7e5a0c9781bcaf1056cb7665fd670867c4b and add new commands/flags CLI: Update SDK to cd875f9f31e3955a9cd07f9df10344313f62f357 and add new commands/flags Oct 9, 2026
- Bump github.com/kernel/kernel-go-sdk to 6f3ae15351013fd71e5d554b69d7e532e1e592db
- Add --video-memory (2GiB|4GiB) to `kernel browsers create` for
  BrowserNewParams.VideoMemory (GPU VRAM tier)
- Show Video Memory in browser get/create output when present

Tested: browsers create --gpu --video-memory 2GiB (get shows Video Memory 2GiB,
Memory 6GiB; deleted afterwards); --video-memory 4GiB reached the API (tier at
capacity); invalid values rejected client-side; go test ./cmd -run TestBrowsers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to cd875f9f31e3955a9cd07f9df10344313f62f357 and add new commands/flags CLI: Update SDK to 6f3ae15351013fd71e5d554b69d7e532e1e592db and add new commands/flags Oct 9, 2026
SDK change is documentation-only (1Password fill_unknown may now carry
error_code autosubmitFailed; inspect the page after an uncertain fill).
The CLI already prints error_code for any 1pw_fill status and its help
text already reflects the new guidance. Full enumeration found no gaps.

Tested: go build ./..., go vet ./..., go test ./...

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kernel-internal kernel-internal Bot changed the title CLI: Update SDK to 6f3ae15351013fd71e5d554b69d7e532e1e592db and add new commands/flags CLI: Update SDK to f737b63ffd168cc67bf0158b961ca3275c94bd1c and add new commands/flags Oct 9, 2026
@yummybomb
yummybomb merged commit 492c59f into main Oct 9, 2026
8 checks passed
@yummybomb
yummybomb deleted the cli-coverage-update branch October 9, 2026 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant