Skip to content

fix: Node 22 for WSL - #15

Merged
ADITYA-tp01 merged 1 commit into
mainfrom
fix/node22
Aug 29, 2026
Merged

fix: Node 22 for WSL#15
ADITYA-tp01 merged 1 commit into
mainfrom
fix/node22

Conversation

@ADITYA-tp01

@ADITYA-tp01 ADITYA-tp01 commented Aug 29, 2026

Copy link
Copy Markdown
Owner

User description

TrueForge requires Node 22+.


CodeAnt-AI Description

Use Node.js 22 when setting up TrueForge in WSL

What Changed

  • New WSL setups now install Node.js 22 instead of Node.js 20
  • Existing WSL Node.js installations are left unchanged

Impact

✅ TrueForge-compatible WSL setup
✅ Fewer installation failures on new environments

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

@ADITYA-tp01
ADITYA-tp01 merged commit 13097c1 into main Aug 29, 2026
@codeant-ai

codeant-ai Bot commented Aug 29, 2026

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 1c485d1 Aug 29, 2026 · 23:03 23:04

@codeant-ai

codeant-ai Bot commented Aug 29, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Require Node.js 22 for TrueForge in WSL

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 5 minutes

Grey Divider

AI Description

• Upgrades the WSL Node.js bootstrap from version 20 to version 22.
• Aligns first-time WSL setup with TrueForge's minimum runtime requirement.
High-Level Assessment

Updating the existing NodeSource bootstrap target is the most direct fix because it preserves the current installation flow while satisfying TrueForge's Node.js 22+ requirement.

Files changed (1) +2 / -2

Bug fix (1) +2 / -2
start.ps1Upgrade the WSL Node.js bootstrap to version 22 +2/-2

Upgrade the WSL Node.js bootstrap to version 22

• Changes the first-time WSL installation message and NodeSource setup URL from Node.js 20 to 22, ensuring newly provisioned environments support TrueForge.

start.ps1

@codeant-ai codeant-ai Bot added the size:XS This PR changes 0-9 lines, ignoring generated files label Aug 29, 2026
@github-actions

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (2) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Alternate setup installs Node 20 🐞 Bug ≡ Correctness
Description
The repository's dedicated setup-wsl.ps1 path still downloads setup_20.x, so a fresh WSL setup
through that script installs a Node version that does not satisfy TrueForge's Node 22+ requirement.
Updating only start.ps1 leaves this sibling WSL provisioning path broken.
Code

start.ps1[R63-64]

+    Write-Host "  Installing Node.js 22 in WSL (first time only)..." -ForegroundColor Yellow
+    wsl -d Ubuntu -- bash -c 'curl -fsSL https://deb.nodesource.com/setup_22.x -o /tmp/ns.sh'
Relevance

●● Moderate

Accepted precedent favors cross-script setup consistency, but no close Node-version sibling-path
precedent was found.

PR-#5

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
setup-wsl.ps1 identifies itself as the one-time WSL setup for TrueForge, but its installation
command explicitly uses NodeSource setup_20.x and then invokes npm to install TrueForge. This
directly contradicts the Node 22 provisioning introduced in start.ps1.

setup-wsl.ps1[1-3]
setup-wsl.ps1[21-29]
start.ps1[59-77]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The main startup path now provisions Node 22, but the dedicated WSL setup script still provisions Node 20 before installing TrueForge.

## Issue Context
Both scripts set up TrueForge under Ubuntu WSL and must enforce the same Node 22+ prerequisite.

## Fix Focus Areas
- start.ps1[63-64]
- setup-wsl.ps1[21-28]

Change the dedicated setup script to install Node 22 and validate/upgrade existing older Node installations rather than checking only whether `node` exists.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Informational

2. Existing Node 20 survives 🐞 Bug ≡ Correctness
Description
start.ps1 runs the NodeSource 22 setup only when /usr/bin/node is absent, so machines previously
provisioned with Node 20 skip the new installation and then attempt to install/run TrueForge on an
unsupported runtime. This makes the fix ineffective for the existing WSL environments most likely to
need the upgrade.
Code

start.ps1[64]

+    wsl -d Ubuntu -- bash -c 'curl -fsSL https://deb.nodesource.com/setup_22.x -o /tmp/ns.sh'
Relevance

● Weak

A same-PR precedent rejected enforcing minimum Node versions beyond checking command presence.

PR-#5

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The branch checks only for the existence of /usr/bin/node; lines 63-66 containing the new Node 22
setup are unreachable whenever Node 20 is already installed. The script immediately proceeds to
install TrueForge afterward, without any version validation.

start.ps1[59-77]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The WSL setup treats any `/usr/bin/node` as sufficient, so existing Node 20 installations never receive the Node 22 repository or package upgrade.

## Issue Context
TrueForge requires Node 22+, and this PR is intended to migrate WSL installations to that version.

## Fix Focus Areas
- start.ps1[61-66]

Parse `node --version` in WSL and run the NodeSource 22 setup plus `apt-get install` whenever Node is missing or its major version is below 22. Verify the resulting version before continuing to TrueForge installation.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
Review mode: ⚖️ Balanced

Grey Divider

Tip of the day
💡 Did you know, you can group findings by type and pick your Finding display, from Minimal to Full

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread start.ps1
Comment on lines +63 to +64
Write-Host " Installing Node.js 22 in WSL (first time only)..." -ForegroundColor Yellow
wsl -d Ubuntu -- bash -c 'curl -fsSL https://deb.nodesource.com/setup_22.x -o /tmp/ns.sh'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

2. Alternate setup installs node 20 🐞 Bug ≡ Correctness

The repository's dedicated setup-wsl.ps1 path still downloads setup_20.x, so a fresh WSL setup
through that script installs a Node version that does not satisfy TrueForge's Node 22+ requirement.
Updating only start.ps1 leaves this sibling WSL provisioning path broken.
Agent Prompt
## Issue description
The main startup path now provisions Node 22, but the dedicated WSL setup script still provisions Node 20 before installing TrueForge.

## Issue Context
Both scripts set up TrueForge under Ubuntu WSL and must enforce the same Node 22+ prerequisite.

## Fix Focus Areas
- start.ps1[63-64]
- setup-wsl.ps1[21-28]

Change the dedicated setup script to install Node 22 and validate/upgrade existing older Node installations rather than checking only whether `node` exists.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Comment thread start.ps1
Comment on lines +64 to 65
wsl -d Ubuntu -- bash -c 'curl -fsSL https://deb.nodesource.com/setup_22.x -o /tmp/ns.sh'
wsl -d Ubuntu -- bash -c 'sudo bash /tmp/ns.sh'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: The downloaded script is executed as root without pinning or verifying its contents. Because the remote setup_22.x endpoint is mutable, a repository compromise, DNS/proxy compromise, or malicious upstream change would cause arbitrary root commands to run whenever this setup path executes. Use a trusted, integrity-verified installation artifact or verify a pinned checksum/signature before invoking it with sudo. [security]

Severity Level: Critical 🚨
- ❌ Compromised NodeSource delivery can execute as WSL root.
- ❌ WSL files and credentials may be modified or exfiltrated.
- ⚠️ Fresh WSL setup depends on mutable third-party content.

Use CodeAnt Skill Fix in Cursor Fix in VSCode Claude

Prompt for AI Agent 🤖
This is a comment left during a code review.

**Path:** start.ps1
**Line:** 64:65
**Comment:**
	*Security: The downloaded script is executed as root without pinning or verifying its contents. Because the remote `setup_22.x` endpoint is mutable, a repository compromise, DNS/proxy compromise, or malicious upstream change would cause arbitrary root commands to run whenever this setup path executes. Use a trusted, integrity-verified installation artifact or verify a pinned checksum/signature before invoking it with `sudo`.

Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix
👍 | 👎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant