ScienceDiscovery是专为科学研究打造的一站式AI科研工作台。依托该平台,科研人员能够一站式高效完成“文献阅读、假设提出、代码编写、实验试错、参数调优”这一极为繁琐的科研探索流程。
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
docs(deploy): walk a Docker user from build to a signed-in browser Rewrite the Docker section of the deployment guide as numbered steps that end in a signed-in browser and a configured model, and add what a first deployment actually runs into: the data directory must exist before up or Docker creates it as root and the entry point refuses it; the sign-in URL in the log always names container port 4310, so a changed SCIENCE_AGENT_PUBLISH_PORT has to be substituted; the first start creates the starter Python environment in the background; the second instance needs its own pre-created data directory. Group the environment variables into orchestration, container and image layers so a key set in the wrong layer stops being a silent no-op, complete the Docker tables in the configuration reference (project name, image tag, host data directory, log and context settings, SSH config; drop the micromamba mirror URL, which the image does not need), and add a troubleshooting section for build, uid/gid, port, token, sandbox, proxy, host-side model, provisioning and health-check questions. Mirror the changes in the English guide and the deploy skill. | 10 天前 | |
refactor: consolidate plugin contributions into owning component packages | 15 天前 | |
first commit | 1 个月前 | |
ci(codearts): run the auto merge on the light image The build task now takes the image as a bare name:tag under the organisation's registry, so a job can pick one. The auto merge reads CODEOWNERS, calls GitCode and counts commits; it opened none of the toolchain, emulator or 3.1 GB guest image it was pulling, and that pull was half of its first run's eighty-six seconds. The test layers keep the console default, which is still the full image, so this changes one job and nothing else. | 23 天前 | |
ci(github): start the Docker job from the documented .env as the runner user The job started the stack with a bare mkdir -p data && docker compose up -d. On a hosted runner that fails twice before any contract check runs: the runner account is not uid 1000, so the container (which Compose runs as the ids .env names, defaulting to 1000) cannot write the bind mount the runner just created and the entry point exits; and with no .env at all, every forwarded key interpolates to an empty string, so the check that a key from .env.docker.example reaches the container environment can only fail. Follow the guide's first-run sequence instead: copy the example .env, write the invoking user's ids into it, and start. SD_PORT is written into the same file so a local replay on a spare port publishes where the job polls. | 10 天前 | |
feat(evolve): short run titles and hand the winning text to the agent Titles. A run's goal is the user's whole brief, kept verbatim because the search reads it, and the panel header printed all of it: a paragraph of constraints and a scoring rubric in a 16px heading. evolveShortTitle() keeps the first sentence, drops a leading "任务:" label and cuts at a fixed width; the panel shows that with the full task in a "Full task" fold, and the run card shows it too, with the whole statement still in its tooltip. Results. get_evolve_run returned scores and a one-line change summary, so an agent asked to apply a finished search had nothing to write and set about rebuilding the program from the summary, which yields one that was never scored. The winning text was already published as an artifact, but nothing said what it was called. Now a finished search that beat its starting point returns: - the winner's full text in its own <best_candidate> block, cut at 30,000 characters with the real length and the artifact name when it is longer; - resultArtifact, the artifact whose version 2 is the winner; - bestCodeHash. The winner is the node the engine names in search_finished, the same one the orchestrator publishes, and a search that is still running or that nothing beat returns none. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> | 10 天前 | |
feat(model): 模型目录改为运行时快照并映射 models.dev - schema: MODEL_CATALOG 常量删除,改为进程内可替换的目录快照。 lookup/list/constrain 全部读取当前快照;未安装快照时一律返回未知, 调用方现有的"未知"分支即是降级路径,不再有编译期内置数据 - schema/models-dev: 唯一读取 models.dev 字段名的映射层。上游没有的事实 保持缺失;协议族与变种不从上游猜测——Anthropic 只接受 budget_tokens 的 模型显式映射为 anthropic-legacy,Kimi K3 的常推理契约以产品覆盖表取胜; modes 不从上游推导,思考开关仍由协议变种决定 - 价格按端点归属:预设映射表逐条声明上游 provider 与内置预设的对应关系, 国内端点对应上游 -cn 列表;智谱只列出 z.ai 而我们连 bigmodel.cn, 因此只取能力事实不取价格;本地 Ollama 不映射任何托管价目 - packages/model: fetchModelsDevCatalog 下载并校验目录文档,走既有代理 dispatcher,失败抛出可读的 ModelCatalogFetchError - 目录端点写入 config/external-urls.json,发布与运行时共用同一来源 | 1 个月前 | |
docs(evolve): name the single entry /evolve-design everywhere The composer already has one entry: the algorithm picker opens only for /evolve-design and no /evolve command is handled. The docs and code comments still described the feature as /evolve, which reads as a second entry. Rename those mentions to /evolve-design in the explanation, how-to, README and REST reference pages (en and zh) and in comments. Comments and prose only; the /api/evolve/... routes are untouched. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> | 10 天前 | |
feat(evolve): short run titles and hand the winning text to the agent Titles. A run's goal is the user's whole brief, kept verbatim because the search reads it, and the panel header printed all of it: a paragraph of constraints and a scoring rubric in a 16px heading. evolveShortTitle() keeps the first sentence, drops a leading "任务:" label and cuts at a fixed width; the panel shows that with the full task in a "Full task" fold, and the run card shows it too, with the whole statement still in its tooltip. Results. get_evolve_run returned scores and a one-line change summary, so an agent asked to apply a finished search had nothing to write and set about rebuilding the program from the summary, which yields one that was never scored. The winning text was already published as an artifact, but nothing said what it was called. Now a finished search that beat its starting point returns: - the winner's full text in its own <best_candidate> block, cut at 30,000 characters with the real length and the artifact name when it is longer; - resultArtifact, the artifact whose version 2 is the winner; - bestCodeHash. The winner is the node the engine names in search_finished, the same one the orchestrator publishes, and a search that is still running or that nothing beat returns none. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> | 10 天前 | |
docs(deploy): gate the sandbox on the real probe instead of a sysctl The deployment guides and the deploy skill presented kernel.apparmor_restrict_unprivileged_userns=0 as a hard prerequisite on Ubuntu 24.04+, and the skill told the assistant to stop and ask for sudo sysctl -w ...=0 whenever the value was 1. That restriction is configured per AppArmor profile, so a host can leave it at 1 and still allow the sandbox: on an Ubuntu 24.04 host with the value at 1, both the host preflight and the in-container probe pass. Following the old text means asking a user to change a kernel switch for a working environment. What actually decides is the probe the product runs — the capability detection in packages/sandbox-capability and the preflight in the shared entry point. The guides now state that, give the reproducible in-container probe command, and reduce the sysctl to the third diagnostic after the container's security_opt and the host's AppArmor profiles. The entry-point warning and SANDBOX_UNUSABLE_HINT carry the same ordering, so the runtime text no longer contradicts the documentation. The probe command keeps its outer sh -c: with bwrap as the first process of a docker compose exec session, loopback setup fails for reasons that have nothing to do with sandbox capability, and pasting the command without the wrapper reads as a false negative. The Docker section also named .sciencediscovery-data/... as the micromamba seed target. That is the host-process default; under Compose the data directory is the bind mount, so the path is now written as it exists. | 12 天前 | |
feat(evolve): short run titles and hand the winning text to the agent Titles. A run's goal is the user's whole brief, kept verbatim because the search reads it, and the panel header printed all of it: a paragraph of constraints and a scoring rubric in a 16px heading. evolveShortTitle() keeps the first sentence, drops a leading "任务:" label and cuts at a fixed width; the panel shows that with the full task in a "Full task" fold, and the run card shows it too, with the whole statement still in its tooltip. Results. get_evolve_run returned scores and a one-line change summary, so an agent asked to apply a finished search had nothing to write and set about rebuilding the program from the summary, which yields one that was never scored. The winning text was already published as an artifact, but nothing said what it was called. Now a finished search that beat its starting point returns: - the winner's full text in its own <best_candidate> block, cut at 30,000 characters with the real length and the artifact name when it is longer; - resultArtifact, the artifact whose version 2 is the winner; - bestCodeHash. The winner is the node the engine names in search_finished, the same one the orchestrator publishes, and a search that is still running or that nothing beat returns none. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> | 10 天前 | |
refactor(skills): trim evolve-design by 40% and move the custom_script contract out SKILL.md loads whole every time the skill triggers, and at 21.7KB much of it restated what the create_evolve_run tool already carries or told a measured anecdote at length. - Drop the cPuct / priorExponent walkthrough: the tool's parameter descriptions already hold the ranges and the reasoning. The skill keeps when to reach for each and that search is left out by default. - Move the custom_script evaluator contract, the error rule the probe enforces, how the script runs and the "evaluator reads nothing" constraint to references/custom-script.md, read only when that mode is chosen. SKILL.md keeps the one-line rule and points to it. - Cut the mode list and the "do not score a broken copy" passage down to what the tool descriptions do not say, and shorten the measured anecdotes to one clause each, keeping the rule and its reason. The four checkpoints, the sizing numbers, and every rule the probe or schema enforces are unchanged. SKILL.md goes from 21,685 to 12,983 bytes; the reference adds 2,633 on demand. Version 1.0.0 -> 1.1.0 in the frontmatter and in BUILT_IN_VERSIONS. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> | 10 天前 | |
test(e2e): follow two UI strings that moved into the message catalogue E2E (mocked) went red on the mirror with 4 journeys failing and the job taking 16.6 minutes. Two root causes, one class: a UI string moved from a component's hardcoded Chinese into the message catalogue, and journeys that located elements by the old text stopped finding them. Most then burned their whole test budget, so the failures surfaced as timeouts and did not read like a wording problem at all. The provider editor's credential field. The local-token onboarding work renamed it from "LLM API 令牌" to "外部模型 API Key" / "External model API Key", deliberately, so a model provider's key reads as distinct from the local service access token. The journey added with that change uses the new label; three older ones were left on the old one: waiting for getByRole('dialog', { name: '系统设置' }) .getByRole('region', { name: '服务商编辑器' }) .getByLabel('LLM API 令牌') 服务商编辑器 and 服务商名称 resolve in that same chain, so the page is Chinese and only this one label is gone — a rename, not a locale problem. journey-model-settings failed its visibility check outright, while journey-first-run and journey-provider-model-catalog blocked on fill for 3 and 4 minutes, which is where the job's 16.6 minutes went. Nine call sites across the three files take the new label; all three already pin locale: "zh-CN", and no other assertion changed. The Idea Tree journey's locale. It reads the research surface in Chinese from end to end but never said so, which worked while those strings were hardcoded and rendered Chinese in any locale. They are catalogue entries now, and Playwright gives Chromium en-US by default, so detectLocale() picks en and the first select is looked up under a label the page never renders. Everything after it was equally exposed: ideaResearch.controlsAria, progressAria, viewProgress, the pause/continue/end controls and every status word come from the catalogue too. test.use({ locale: "zh-CN" }) covers all of them and matches the three journeys above. The option values it selects — water-treatment-materials/v1 and standard — are locale-independent and unchanged. Only Playwright specs change here; no product code. Verified on this commit: pnpm ci:ut exit 0 (2676 Node passed / 0 failed / 8 skipped; evolve 316 passed; memory-graph 83 passed / 77 skipped; gateway 26 tests OK; paper 2 tests OK), pnpm ci:st exit 0 (agent loop smoke PASS), pnpm ci:e2e exit 0 (39 passed / 0 failed / 2 skipped; check-e2e-meta 44 spec files, 0 errors, 11 legacy warnings — unchanged). The four journeys also pass individually: 12.5 s, 6.5 s, 28.8 s and 8.8 s, against 3 min, 10 s, 4 min and 180 s of failure before. | 11 天前 | |
chore: empty file to exercise the merge-request CI trigger Verifies that .gitcode/workflows/ci.yml fires on pull_request, which has only ever been confirmed via explicit workflow_dispatch. Delete this file before merging; the change carries no product content. | 1 个月前 | |
feat(config)!: move the data directory to .sciencediscovery-data Both launchers wrote their runtime root to an undecorated directory: the repository launcher to <repo>/data, which was never gitignored and is easy to mistake for source, and the single-file launcher to ./science-discovery-data. Default both to .sciencediscovery-data, resolved from the repository root and from the launcher's working directory respectively. Changed in every place that declared a default: scripts/start-stack.sh, the API and Runner config loaders, the memory-graph logging config, .env.example, and the launcher CLI options and usage text. Existing installations are migrated once rather than orphaned. start-stack.sh moves an existing data/ directory, using the [compat] idiom the script already uses for the SCIENCE_AGENT_* to SCIENCE_DISCOVERY_* rename. The launcher now walks both former defaults, science-discovery-data before the older science-agent-data, so a host on either one is carried over; migrateLegacyDirectory already refuses to replace an existing target, so the newer wins and the older logs a skip. Neither path runs when the data directory is set explicitly. .dockerignore excludes the new name as well. That exclusion is what keeps bootstrap tokens and model-secrets.key out of the build context, so it has to move with the default; data/ stays excluded for un-migrated checkouts. Docker keeps its own /app/data bind mount. | 1 个月前 | |
fix(docker): forward the usage exchange-rate settings into the container The configuration reference lists the four SCIENCE_AGENT_USAGE_EXCHANGE_RATE* keys as Docker variables, but docker-compose.yml never forwarded them, so a deployment that cannot reach the public rate source had no way to disable the conversion or name a mirror. Forward them like the other container-level keys, with an empty value meaning the built-in default, and add them to .env.docker.example. | 10 天前 | |
feat(connectors): add read-only local LLM Wiki integration | 21 天前 | |
first commit | 1 个月前 | |
merge: 同步上游 main(75 个提交) 九处冲突,都在两边同时动过的地方。逐处的取舍: ** packages/model/src/client.ts(6 处)——采用上游的 thinking 抽象,弃用我的。** 我之前加的是 thinking?: "disabled" | "enabled",一个由环境变量控制的粗糙开关; 上游现在有 thinkingEffort / thinkingMode / chatThinkingFields(),按 provider 分派(deepseek、kimi-k3 各有各的字段),并且走模型档案而不是部署级环境变量。 上游那套严格更好,我的整个删掉。 截断检测(finish_reason: "length" 与 Anthropic 的 stop_reason: "max_tokens") 保留,挂到上游更干净的类型窄化之上——那部分两边不重叠。 **native-agent/index.ts(2 处)**:上游往工具注册表里加了 ToolOutputStore, 我们加了 evolve 能力包,两个 spread 并存。历史归一化采用上游简化后的写法。 **App.tsx(4 处)**:上游新增了懒加载的图谱浏览器和模型目录导入,我们有 evolve 面板和轮询常量——都是并列新增。有一处 JSX 三元被拼接切断,补回了闭合。 **其余 3 处**是纯新增撞在一起(schema 导入、CSS 块、runner 测试导入),各留一份。 图谱边线颜色采用上游的新色值,我们新增的五种 evolve 边跟着改成同色。 测试:web 558、API 625(5 条既有环境失败:MCP stdio ×3、PDF 抽取 ×2)、 python evolve 233、memory-graph 75。全仓构建与类型检查通过。 部署机上还缺上游新增的 config/external-urls.json——不补的话 70 条测试因 model_catalog.api_json 缺失而失败。已补。 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> | 1 个月前 | |
first commit | 1 个月前 | |
first commit | 1 个月前 | |
docs: keep GitCode fork owner as a per-operator login Do not hard-code a person. Each contributor forks under their own GitCode account, resolves the login from gitcode auth, and opens the merge request with --head <gitcode-login>:<branch>. | 21 天前 | |
fix(docker): derive the image's workspace manifests from the build context The dependency layer copied each workspace package.json by name so that editing application source would not invalidate the pnpm install cache. That list only stayed correct while somebody remembered to update it: packages/agent-runtime was renamed to packages/runtime-core and nothing followed, leaving docker compose build failing on a path that no longer exists. The list had also fallen behind in bulk — it named 7 of the 32 workspace projects the lockfile records, so correcting the one path would still have failed in pnpm install --frozen-lockfile. A separate stage now extracts every package.json from the build context and the builder copies that whole extract. BuildKit keys COPY --from=<stage> on the copied content, which is byte-identical while only application source changes, so the install layer keeps the cache the handwritten list was there to protect. Nothing in the repository builds the product image, which is why the drift survived; scripts/docker-build-context.test.mjs now fails an ordinary architecture:check run when a Dockerfile build-context source is missing, when the dependency layer names workspace manifests one by one again, or when a lockfile importer has lost its manifest. | 12 天前 | |
first commit | 1 个月前 | |
docs(auth): explain automatic local sign-in links | 13 天前 | |
docs(auth): explain automatic local sign-in links | 13 天前 | |
fix(deps): move undici, ajv and fflate past their reported CVEs undici 8.7.0 -> 8.9.0 covers CVE-2026-15157, CVE-2026-16728, CVE-2026-16729, CVE-2026-13697 and CVE-2026-14643. ajv 8.17.1 -> 8.18.0 covers CVE-2025-69873. fflate 0.8.2 -> 0.8.3 covers CVE-2026-45820. @modelcontextprotocol/sdk depends on ajv ^8.17.1, and pnpm keeps the already locked 8.17.1 for it, so the affected copy would stay in the tree beside our own 8.18.0 pin. A workspace override collapses both onto 8.18.0, which still satisfies that range. The third-party notice tracks the shipped versions, so its ajv, fflate and undici entries move with them; fflate also reissued its licence under a later copyright year. | 10 天前 | |
fix(docker): forward the usage exchange-rate settings into the container The configuration reference lists the four SCIENCE_AGENT_USAGE_EXCHANGE_RATE* keys as Docker variables, but docker-compose.yml never forwarded them, so a deployment that cannot reach the public rate source had no way to disable the conversion or name a mirror. Forward them like the other container-level keys, with an empty value meaning the built-in default, and add them to .env.docker.example. | 10 天前 | |
feat(connectors): add read-only local LLM Wiki integration | 21 天前 | |
fix(docker): derive the image's workspace manifests from the build context The dependency layer copied each workspace package.json by name so that editing application source would not invalidate the pnpm install cache. That list only stayed correct while somebody remembered to update it: packages/agent-runtime was renamed to packages/runtime-core and nothing followed, leaving docker compose build failing on a path that no longer exists. The list had also fallen behind in bulk — it named 7 of the 32 workspace projects the lockfile records, so correcting the one path would still have failed in pnpm install --frozen-lockfile. A separate stage now extracts every package.json from the build context and the builder copies that whole extract. BuildKit keys COPY --from=<stage> on the copied content, which is byte-identical while only application source changes, so the install layer keeps the cache the handwritten list was there to protect. Nothing in the repository builds the product image, which is why the drift survived; scripts/docker-build-context.test.mjs now fails an ordinary architecture:check run when a Dockerfile build-context source is missing, when the dependency layer names workspace manifests one by one again, or when a lockfile importer has lost its manifest. | 12 天前 | |
fix(deps): move undici, ajv and fflate past their reported CVEs undici 8.7.0 -> 8.9.0 covers CVE-2026-15157, CVE-2026-16728, CVE-2026-16729, CVE-2026-13697 and CVE-2026-14643. ajv 8.17.1 -> 8.18.0 covers CVE-2025-69873. fflate 0.8.2 -> 0.8.3 covers CVE-2026-45820. @modelcontextprotocol/sdk depends on ajv ^8.17.1, and pnpm keeps the already locked 8.17.1 for it, so the affected copy would stay in the tree beside our own 8.18.0 pin. A workspace override collapses both onto 8.18.0, which still satisfies that range. The third-party notice tracks the shipped versions, so its ajv, fflate and undici entries move with them; fflate also reissued its licence under a later copyright year. | 10 天前 | |
fix(deps): move undici, ajv and fflate past their reported CVEs undici 8.7.0 -> 8.9.0 covers CVE-2026-15157, CVE-2026-16728, CVE-2026-16729, CVE-2026-13697 and CVE-2026-14643. ajv 8.17.1 -> 8.18.0 covers CVE-2025-69873. fflate 0.8.2 -> 0.8.3 covers CVE-2026-45820. @modelcontextprotocol/sdk depends on ajv ^8.17.1, and pnpm keeps the already locked 8.17.1 for it, so the affected copy would stay in the tree beside our own 8.18.0 pin. A workspace override collapses both onto 8.18.0, which still satisfies that range. The third-party notice tracks the shipped versions, so its ajv, fflate and undici entries move with them; fflate also reissued its licence under a later copyright year. | 10 天前 | |
first commit | 1 个月前 |
ScienceDiscovery
ScienceDiscovery是专为科学研究打造的一站式AI科研工作台。依托该平台,科研人员能够一站式高效完成“文献阅读、假设提出、代码编写、实验试错、参数调优”这一极为繁琐的科研探索流程。
English | 中文
Warning
ScienceDiscovery 不是多用户生产服务。API、runner 与 gateway 默认只监听回环;API 使用一个 bearer token 且不终止 TLS。监听其他网卡必须是可信、受保护网络中的显式部署选择。Python、R 和 shell 命令在 fail-closed 的平台沙箱中运行(Linux 使用 Bubblewrap,macOS 源码模式使用 Seatbelt);控制 API、gateway、PDF worker 以及发往已配置模型/数据提供方的请求在沙箱外作为受信任控制面操作执行。
项目定位
ScienceDiscovery是专为科学研究打造的一站式AI科研工作台。依托该平台,科研人员能够一站式高效完成“文献阅读、假设提出、代码编写、实验试错、参数调优”这一极为繁琐的科研探索流程。
特性
- 海量资源一键配置与高效接入:通过平台内置的科研数据库 Connector,实现文献库与数据库的一键快速配置,快速获取海量前沿文献与核心试验数据;
- 安全沙箱环境下的自主代码探索:支持智能体在安全隔离的沙箱环境中自主编写、调试并运行 Python、R 或 Shell 代码,为复杂科学数据处理提供稳定环境;
- 复杂科研任务的自动拆解与动态执行:凭借强大的任务规划与多智能体协同能力,系统可自动拆解复杂科研任务,动态编排并调用 300+ 跨领域 Skills;
- 科研流程全链路可溯源:平台将完整展现全流程工作流,并提供包含代码、环境和日志在内的全链路产物溯源,确保科研全流程的高可信度。
相关文档
环境要求
预打包二进制是主要用户路径,其他部署方式单独记录在部署指南中。
| 路径 | 宿主要求 |
|---|---|
| 预打包二进制 | Linux x86_64/aarch64、bubblewrap |
| 本地源码模式 | Linux x86_64/aarch64 或 macOS x64/arm64、Node.js 22.19+、pnpm 11.1.2、Python 3、uv 0.9+、Git;Linux 另需 Bubblewrap,macOS 使用系统内置 Seatbelt |
| Docker | Linux x86_64/aarch64、Docker Engine 24+、Compose v2,以及可用的无特权用户命名空间 |
源码模式下 Gateway 要求 Python 3.12,uv 会在需要时将其安装到服务环境。托管科学环境使用应用固定版本的 micromamba,不要求系统安装 Python、R 或 conda。预打包二进制与 Docker 仍仅支持 Linux;本地源码模式同时支持 macOS,具体见部署指南。
安装
准备与宿主架构匹配的 ScienceDiscovery 可执行文件。二进制打包、本地源码模式与 Docker 流程见部署指南。
快速开始
在 ScienceDiscovery 可执行文件所在目录启动服务:
chmod +x ./ScienceDiscovery
./ScienceDiscovery serve
另开终端执行 curl -fsS http://127.0.0.1:4310/health。随后打开启动日志中的 Open to sign in 链接,浏览器会自动保存本地服务访问令牌;它与外部模型 API Key 不同,请勿分享该链接。然后在 系统配置 → Global defaults 配置任务模型。第一次任务见快速开始教程;二进制打包、本地源码模式与 Docker 见部署指南。
许可证
本产品仅作为流程编排工具,不包含 AI 模型能力;用户在连接 AI 模型用于特定业务场景时,需自行承担欧盟 AI 法案等相关合规义务。
项目介绍
ScienceDiscovery是专为科学研究打造的一站式AI科研工作台。依托该平台,科研人员能够一站式高效完成“文献阅读、假设提出、代码编写、实验试错、参数调优”这一极为繁琐的科研探索流程。
定制我的领域