From a46c68a7cfcddba05d6b03e71dce495ea77d8e5e Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 3 Oct 2026 20:11:53 -0700 Subject: [PATCH 1/9] deps: bump @cldmv/fix-headers to 2.1.4 and restamp file headers Bumps @cldmv/fix-headers to 2.1.4 and re-runs npm run fix:headers. 0 files' headers were restamped. --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index f1c5fa2..b61a610 100644 --- a/package-lock.json +++ b/package-lock.json @@ -18,7 +18,7 @@ }, "devDependencies": { "@cldmv/configs": "^1.2.0", - "@cldmv/fix-headers": "^2.1.1", + "@cldmv/fix-headers": "^2.1.4", "@cldmv/vitest-runner": "^1.2.0", "@vitest/coverage-v8": "^5.0.0", "vitest": "^5.0.0" @@ -96,9 +96,9 @@ } }, "node_modules/@cldmv/fix-headers": { - "version": "2.1.1", - "resolved": "https://registry.npmjs.org/@cldmv/fix-headers/-/fix-headers-2.1.1.tgz", - "integrity": "sha512-08xW44RvtrKUCTOjUFKHyrDvx6rT70zGqgRR+tdW0R9ElZrHwSg25xCRrZD+U7Dmj5fK9KmtuOWPjZtJYSfzYA==", + "version": "2.1.4", + "resolved": "https://registry.npmjs.org/@cldmv/fix-headers/-/fix-headers-2.1.4.tgz", + "integrity": "sha512-PvCKMztN9k+jOjEpMCANMaDIkNW7cs2qp5P73JVzResk1+DfqhoZVqT9jpTT8cUu+6OGszsNqj8/X0Q9IhfNtg==", "dev": true, "license": "Apache-2.0", "dependencies": { diff --git a/package.json b/package.json index bc39885..a5ffdc3 100644 --- a/package.json +++ b/package.json @@ -44,7 +44,7 @@ }, "devDependencies": { "@cldmv/configs": "^1.2.0", - "@cldmv/fix-headers": "^2.1.1", + "@cldmv/fix-headers": "^2.1.4", "@cldmv/vitest-runner": "^1.2.0", "@vitest/coverage-v8": "^5.0.0", "vitest": "^5.0.0" From 72764a49ed10384d1a35804d958622a9eb50185c Mon Sep 17 00:00:00 2001 From: "cldmv-bot[bot]" <230771808+cldmv-bot[bot]@users.noreply.github.com> Date: Sun, 4 Oct 2026 03:29:03 +0000 Subject: [PATCH 2/9] chore: bump version to 1.0.10 --- package-lock.json | 4 ++-- package.json | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index b61a610..c3cc54b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@cldmv/wol-proxy", - "version": "1.0.9", + "version": "1.0.10", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@cldmv/wol-proxy", - "version": "1.0.9", + "version": "1.0.10", "hasInstallScript": true, "license": "GPL-3.0", "dependencies": { diff --git a/package.json b/package.json index a5ffdc3..1d76df0 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@cldmv/wol-proxy", - "version": "1.0.9", + "version": "1.0.10", "description": "A simple, cross-platform Wake-on-LAN (WoL) HTTP proxy that lets you power on devices on your network by sending an HTTP request.", "main": "index.js", "scripts": { From 99b53aab605b7af9a7277fcaa90cfd4ba26af9a3 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 3 Oct 2026 20:44:47 -0700 Subject: [PATCH 3/9] docs: backfill changelogs for releases that shipped without one --- docs/changelog/v1/v1.0.0.md | 52 ++++++++++++++++++++++++++++++ docs/changelog/v1/v1.0.1.md | 55 ++++++++++++++++++++++++++++++++ docs/changelog/v1/v1.0.2.md | 63 +++++++++++++++++++++++++++++++++++++ docs/changelog/v1/v1.0.3.md | 35 +++++++++++++++++++++ docs/changelog/v1/v1.0.4.md | 44 ++++++++++++++++++++++++++ docs/changelog/v1/v1.0.5.md | 34 ++++++++++++++++++++ docs/changelog/v1/v1.0.6.md | 51 ++++++++++++++++++++++++++++++ docs/changelog/v1/v1.0.7.md | 52 ++++++++++++++++++++++++++++++ docs/changelog/v1/v1.0.8.md | 35 +++++++++++++++++++++ docs/changelog/v1/v1.0.9.md | 35 +++++++++++++++++++++ 10 files changed, 456 insertions(+) create mode 100644 docs/changelog/v1/v1.0.0.md create mode 100644 docs/changelog/v1/v1.0.1.md create mode 100644 docs/changelog/v1/v1.0.2.md create mode 100644 docs/changelog/v1/v1.0.3.md create mode 100644 docs/changelog/v1/v1.0.4.md create mode 100644 docs/changelog/v1/v1.0.5.md create mode 100644 docs/changelog/v1/v1.0.6.md create mode 100644 docs/changelog/v1/v1.0.7.md create mode 100644 docs/changelog/v1/v1.0.8.md create mode 100644 docs/changelog/v1/v1.0.9.md diff --git a/docs/changelog/v1/v1.0.0.md b/docs/changelog/v1/v1.0.0.md new file mode 100644 index 0000000..45c7b92 --- /dev/null +++ b/docs/changelog/v1/v1.0.0.md @@ -0,0 +1,52 @@ +# wol-proxy v1.0.0 Changelog + +**Release Date**: June 2025 +**Release Type**: Initial release + +--- + +## Overview + +First release of `@cldmv/wol-proxy`, published to npm on 2025-06-29. wol-proxy is a small cross-platform CLI tool and HTTP server that sends Wake-on-LAN (WoL) magic packets, so a device on your network can be powered on by sending an HTTP request. Run it locally as a utility, or on an always-on machine or VM to expose WoL over HTTP. + +The whole implementation is a single file, `index.js`, built on `express` (^5.1.0) and `wake_on_lan` (^1.0.0). + +--- + +## ✨ Features + +### `wol-proxy` command and HTTP server + +- Installs a `wol-proxy` executable (`bin` → `index.js`) that starts an Express server bound to `0.0.0.0`. +- Listens on port **3000** by default; override with the `PORT` environment variable. + +### `POST /wake` + +Accepts a JSON body and broadcasts a magic packet through `wake_on_lan`: + +| Field | Required | Default | Description | +| ------ | -------- | ----------------- | ---------------------------- | +| `mac` | yes | none | Target device MAC address | +| `ip` | no | `255.255.255.255` | Broadcast address to send to | +| `port` | no | `9` | UDP port | + +- Success returns `{ "success": true }` and logs `Sent WoL to via :`. +- A missing `mac` returns HTTP 400 with `{ "error": "MAC required" }`. +- A failure from the WoL library returns HTTP 500 with `{ "error": "" }`. + +### Documentation + +- The README covers usage, a `curl` example, the request options table, a quick test, development setup and the GPL-3.0 license. +- It notes that the server is unauthenticated and recommends a reverse proxy with IP allow-listing or auth, a firewall, or a VPN. +- The README's install command at this release is `npm install -g wol-proxy` (unscoped), while the published package name is `@cldmv/wol-proxy`. + +### Repository + +- A comprehensive `.gitignore` was added and the license is declared as GPL-3.0. + +--- + +## Upgrade notes + +- First release; nothing to upgrade from. +- The server has no authentication. Do not expose it to untrusted networks without a reverse proxy, firewall or VPN in front of it. diff --git a/docs/changelog/v1/v1.0.1.md b/docs/changelog/v1/v1.0.1.md new file mode 100644 index 0000000..ed9101d --- /dev/null +++ b/docs/changelog/v1/v1.0.1.md @@ -0,0 +1,55 @@ +# wol-proxy v1.0.1 Changelog + +**Release Date**: June 2025 +**Release Type**: Patch + +--- + +## Overview + +Adds systemd service support, shipped as a patch release and published to npm on 2025-06-29, about twenty minutes after v1.0.0. A bundled `wol-proxy.service` unit file and a `postinstall.js` script let the tool be set up as a background service on Linux. The HTTP server itself (`index.js`) is unchanged from [v1.0.0](./v1.0.0.md). + +Although it carries a patch version, this is a feature addition, and it changes what `npm install` does: a `postinstall` script now runs on install and, on systemd systems, calls `sudo` to copy a file into `/etc/systemd/system`. It does not change the runtime API and is not a breaking change, but it is behavior you should know about before installing. + +--- + +## ✨ Features + +### Systemd service file + +- New `wol-proxy.service` unit: `ExecStart=/usr/bin/env wol-proxy`, `Restart=on-failure` with `RestartSec=3`, `Environment=PORT=3000`, output to the journal, `WantedBy=multi-user.target`. +- The unit has no `User=` setting, so systemd runs the service as root unless you edit it. + +### `postinstall.js` + +Wired up as the package's `postinstall` script, so it runs on every install of the package (global installs included). What it does: + +- Looks for `/etc/systemd/system`, and failing that `/bin/systemctl`, to decide whether this is a systemd Linux system. Otherwise it prints "Skipping systemd setup" and does nothing. +- On a systemd system it runs `sudo cp wol-proxy.service /etc/systemd/system/wol-proxy.service` followed by `sudo systemctl daemon-reload`, with output attached to the terminal (so `sudo` may prompt for a password). +- It does **not** enable or start the service; it prints the `sudo systemctl enable wol-proxy` and `sudo systemctl start wol-proxy` commands for you to run. +- If the copy fails, it prints a warning to install manually with sudo, and the npm install still succeeds. +- If only `/bin/systemctl` is found (no `/etc/systemd/system` directory), the script builds its destination path under `/bin/systemctl/`, which fails and falls into the warning above. + +### Package contents + +- A `files` whitelist now limits the published package to `index.js`, `postinstall.js`, `wol-proxy.service`, `README.md` and `LICENSE`. +- `publishConfig.access` is set to `public`. + +--- + +## 📚 Documentation + +- The README gains a "Running as a System Service" section: the automatic install attempt, manual setup (copying the bundled unit file from the global npm root), enabling and starting the service, checking status with `systemctl status`, and viewing logs with `journalctl -u wol-proxy -f`. + +--- + +## 🐛 Packaging note + +- `package.json` in this release contains two `"scripts"` keys: the original one with the placeholder `test` script and a second one with only `postinstall`. When parsed, the later key wins, so the effective scripts object is just `{ "postinstall": "node postinstall.js" }` and the placeholder `test` script is dropped. This is cleaned up in [v1.0.2](./v1.0.2.md). + +--- + +## Upgrade notes + +- No breaking changes to the HTTP API or CLI; drop-in for v1.0.0. +- Installing now runs `postinstall.js`, which on systemd Linux uses `sudo` to place a unit file in `/etc/systemd/system` and reload systemd. Nothing is enabled or started automatically. diff --git a/docs/changelog/v1/v1.0.2.md b/docs/changelog/v1/v1.0.2.md new file mode 100644 index 0000000..022391d --- /dev/null +++ b/docs/changelog/v1/v1.0.2.md @@ -0,0 +1,63 @@ +# wol-proxy v1.0.2 Changelog + +**Release Date**: August 2026 +**Release Type**: Patch + +--- + +## Overview + +First release through the CLDMV v4 staging-branch workflow. The headline change is repository tooling: a full set of `CLDMV/.github` v4 workflows, a Vitest-based test suite for the previously untested server, and refreshed transitive dependencies. The release PR was [#7](https://github.com/CLDMV/wol-proxy/pull/7). + +No runtime source changed: `index.js`, `postinstall.js`, `wol-proxy.service` and the README are identical to [v1.0.1](./v1.0.1.md). The only change a consumer can observe is newer resolved versions of Express's transitive dependencies in the repo's lockfile. + +--- + +## 🔧 CI & tooling + +### Adopt CLDMV v4 workflows and Vitest tests ([#4](https://github.com/CLDMV/wol-proxy/pull/4)) + +- Adds the v4 workflow set under `.github/workflows/` (CI, publish, feature-PR opener, next/hotfixes release, next-reset, hotfix-redirector, labeler, PR-title normalizer, master-commit audit, release notify, tag health, major-tag updater, v4 bootstrap, CLA, CodeQL, Scorecard, dependency review, Dependabot auto-merge, stale, welcome, branch retention), all thin callers of `CLDMV/.github` reusable workflows pinned `@v4`, plus `.github/dependabot.yml`. Releases now go through a `next` to `master` release PR. +- Adds a `@cldmv/vitest-runner` test setup: `.configs/vitest.config.mjs` (coverage measured on `index.js`), `tests/run-vitest.mjs`, and two test files that characterize `index.js`: `wake-endpoint.test.vitest.mjs` (the `POST /wake` route with a stubbed `wake_on_lan`) and `port-fallback.test.vitest.mjs` (the `PORT` / default-3000 selection). +- New scripts: `test`, `test:watch`, `coverage`, `ci:coverage`, and placeholder `build` / `build:ci` scripts that only echo (the CI coverage job runs `npm run build`). +- New dev dependencies: `@cldmv/vitest-runner` ^1.2.0, `@vitest/coverage-v8` ^4.1.10, `vitest` ^4.1.10. + +### Test file naming ([#6](https://github.com/CLDMV/wol-proxy/pull/6)) + +- Test files use the `*.test.vitest.mjs` suffix, and the Vitest config's include glob matches it. + +### `package.json` cleanup + +- The duplicated `"scripts"` key from v1.0.1 is merged into a single object. Because the later key used to win when parsed, the effective scripts before this release were only `postinstall`; the merged object keeps `postinstall` and adds the new scripts above. +- Runtime dependency ranges (`express` ^5.1.0, `wake_on_lan` ^1.0.0) are unchanged. + +--- + +## 🔧 Dependencies + +### Transitive security bumps ([#5](https://github.com/CLDMV/wol-proxy/pull/5)) + +Lockfile-only refresh of runtime transitive dependencies; the `package.json` ranges did not change. Consumers installing from the registry resolve their own versions; the lockfile applies to the repo's own CI and local installs. Notable changes: + +- `express` 5.1.0 to 5.2.1 +- `body-parser` 2.2.0 to 2.3.0 +- `qs` 6.14.0 to 6.15.3 +- `path-to-regexp` 8.2.0 to 8.4.2 +- `send` 1.2.0 to 1.2.1 and `serve-static` 2.2.0 to 2.2.1 +- `iconv-lite` 0.6.3 to 0.7.3, `raw-body` 3.0.0 to 3.0.2, `type-is` 2.0.1 to 2.1.0, `debug` 4.4.1 to 4.4.3, `http-errors` 2.0.0 to 2.0.1, `mime-types` 3.0.1 to 3.0.2 +- Smaller bumps to `content-disposition`, `finalhandler`, `range-parser`, `side-channel` and related packages, and removal of the now-unneeded `safe-buffer`. + +The lockfile also now records the package under its scoped name `@cldmv/wol-proxy` at the current version, with `license` GPL-3.0 and `hasInstallScript`, and includes the new dev dependencies. + +--- + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.0.2.md](./v1.0.2.md) — this changelog (added retroactively). + +--- + +## Upgrade notes + +- No breaking changes — drop-in for v1.0.1. +- No runtime code changed; the new files are CI configuration and tests, and the `build` scripts are placeholders. diff --git a/docs/changelog/v1/v1.0.3.md b/docs/changelog/v1/v1.0.3.md new file mode 100644 index 0000000..9ab097a --- /dev/null +++ b/docs/changelog/v1/v1.0.3.md @@ -0,0 +1,35 @@ +# wol-proxy v1.0.3 Changelog + +**Release Date**: August 2026 +**Release Type**: Patch + +--- + +## Overview + +CI-only release: the `ci.yml` concurrency rules are changed so runs that matter for releasing are never cancelled by newer pushes. The release PR was [#9](https://github.com/CLDMV/wol-proxy/pull/9) and carries [#8](https://github.com/CLDMV/wol-proxy/pull/8). + +No runtime code changed, and the lockfile differs from [v1.0.2](./v1.0.2.md) only in the package version. The diff touches `.github/workflows/ci.yml` and the version in `package.json`. + +--- + +## 🔧 CI & tooling + +### Never supersede release-relevant CI runs ([#8](https://github.com/CLDMV/wol-proxy/pull/8)) + +- Pushes to the release base branch (taken from the `CLDMV_RELEASE_BASE` variable, else the repository's default branch), pushes to `next` and `hotfixes`, and the `next` / `hotfixes` release PRs each get a unique concurrency group per run (the run id is appended). +- Feature branches and feature PRs still cancel superseded runs. +- Previously a burst of pushes during a release could cancel a pending run, leaving a red "cancelled" check on the release PR even though nothing had failed. + +--- + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.0.3.md](./v1.0.3.md) — this changelog (added retroactively). + +--- + +## Upgrade notes + +- No breaking changes — drop-in for v1.0.2. +- No runtime code changed. diff --git a/docs/changelog/v1/v1.0.4.md b/docs/changelog/v1/v1.0.4.md new file mode 100644 index 0000000..657b481 --- /dev/null +++ b/docs/changelog/v1/v1.0.4.md @@ -0,0 +1,44 @@ +# wol-proxy v1.0.4 Changelog + +**Release Date**: August 2026 +**Release Type**: Patch + +--- + +## Overview + +Maintenance release: bot-identity wiring in three release workflows and a patch-level bump of the Vitest toolchain. The release PR was [#12](https://github.com/CLDMV/wol-proxy/pull/12), which carries [#10](https://github.com/CLDMV/wol-proxy/pull/10) and [#11](https://github.com/CLDMV/wol-proxy/pull/11). + +No runtime code changed, and the runtime part of the lockfile is identical to [v1.0.3](./v1.0.3.md). Only dev dependencies moved, so only the repo's test and CI toolchain is affected. + +--- + +## 🔧 CI & tooling + +### Recognize the bot identity ([#10](https://github.com/CLDMV/wol-proxy/pull/10)) + +- `feature-pr.yml`, `next-release.yml` and `hotfixes-release.yml` now pass `BOT_NAME` and `BOT_EMAIL` (from the `CLDMV_BOT_NAME` and `CLDMV_BOT_EMAIL` secrets), so bot-authored commits and PRs use the real bot identity. The PR re-triggered the feature-PR opener against the fixed `@v4` workflows. + +--- + +## 🔧 Dependencies + +### Patch group bump ([#11](https://github.com/CLDMV/wol-proxy/pull/11)) + +Dev dependencies only; `package.json` ranges are unchanged and the lockfile moved: + +- `vitest` and `@vitest/coverage-v8` 4.1.10 to 4.1.11, along with the rest of the `@vitest/*` family. +- `vite` 8.2.0 to 8.2.2 and `rolldown` 1.2.1 to 1.2.5, plus smaller transitive bumps (`postcss`, `nanoid`, `@oxc-project/types`) and removal of some unused WASM fallback packages. + +--- + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.0.4.md](./v1.0.4.md) — this changelog (added retroactively). + +--- + +## Upgrade notes + +- No breaking changes — drop-in for v1.0.3. +- No runtime code changed; dev dependencies only. diff --git a/docs/changelog/v1/v1.0.5.md b/docs/changelog/v1/v1.0.5.md new file mode 100644 index 0000000..4adcf1a --- /dev/null +++ b/docs/changelog/v1/v1.0.5.md @@ -0,0 +1,34 @@ +# wol-proxy v1.0.5 Changelog + +**Release Date**: September 2026 +**Release Type**: Patch + +--- + +## Overview + +CI-only release: the `hotfix-redirector` workflow now has the signing secrets it needs so redirected security PRs are signed. The release PR was [#14](https://github.com/CLDMV/wol-proxy/pull/14), carrying [#13](https://github.com/CLDMV/wol-proxy/pull/13). + +No runtime code changed and the lockfile differs from [v1.0.4](./v1.0.4.md) only in the package version. The diff is four added lines in `.github/workflows/hotfix-redirector.yml` plus the version bump. + +--- + +## 🔒 Security & supply chain + +### Sign redirected security PRs ([#13](https://github.com/CLDMV/wol-proxy/pull/13)) + +- `hotfix-redirector.yml` now maps `BOT_NAME`, `BOT_EMAIL`, `BOT_GPG_PRIVATE_KEY` and `BOT_GPG_PASSPHRASE` from the `CLDMV_BOT_*` secrets. +- When a Dependabot security PR is redirected away from `master`, the cherry-picked commit is now signed. Unsigned redirected commits were blocked by the repository's signature rule. + +--- + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.0.5.md](./v1.0.5.md) — this changelog (added retroactively). + +--- + +## Upgrade notes + +- No breaking changes — drop-in for v1.0.4. +- No runtime code changed. diff --git a/docs/changelog/v1/v1.0.6.md b/docs/changelog/v1/v1.0.6.md new file mode 100644 index 0000000..2ff5fa9 --- /dev/null +++ b/docs/changelog/v1/v1.0.6.md @@ -0,0 +1,51 @@ +# wol-proxy v1.0.6 Changelog + +**Release Date**: September 2026 +**Release Type**: Patch + +--- + +## Overview + +Dependency and CI-matrix release. The Vitest toolchain moves to major version 5, the CI Node matrix is raised to match, and `qs` (a transitive dependency of Express) is bumped in the lockfile. The release PR was [#20](https://github.com/CLDMV/wol-proxy/pull/20). + +No runtime source changed. The only runtime-relevant delta is the lockfile resolving `qs` 6.15.3 to 6.16.0; the `package.json` runtime ranges (`express` ^5.1.0, `wake_on_lan` ^1.0.0) are unchanged. Consumers installing from the registry resolve their own `qs`; the lockfile affects the repo's own CI and local installs. + +--- + +## 🔧 Dependencies + +### `qs` 6.15.3 to 6.16.0 ([#16](https://github.com/CLDMV/wol-proxy/pull/16)) + +- Runtime transitive dependency (via Express), lockfile only. It arrived through the hotfix redirector as a copy of Dependabot's original PR ([#15](https://github.com/CLDMV/wol-proxy/pull/15)) and was merged into `next`. + +### Vitest 5 ([#17](https://github.com/CLDMV/wol-proxy/pull/17)) + +- Dev dependencies only. `vitest` and `@vitest/coverage-v8` ranges go from `^4.1.10` to `^5.0.0` (lockfile resolves 5.0.0), with matching `vite` 8.3.0, `rolldown` 1.2.8 and a reshuffled set of `@vitest/*` helper packages. +- `@vitest/coverage-v8` 5.0.0 landed in this same change; its separate Dependabot PR ([#18](https://github.com/CLDMV/wol-proxy/pull/18)) was closed without merging. +- `tests/port-fallback.test.vitest.mjs` was adjusted for Vitest 5: it now flushes the microtask queue explicitly before the macrotask queue, and records the logged message directly instead of reading the spy later, because Vitest 5 clears mocks before every test by default. + +--- + +## 🔧 CI & tooling + +### Node matrix for Vitest 5 ([#19](https://github.com/CLDMV/wol-proxy/pull/19)) + +- `ci.yml` and `publish.yml` default `min_node_version` changes from `20` to `22.12.0` (the floor Vitest 5 runs on) and `max_node_major` from `22` to `26`. + +### Dependabot grouping ([#21](https://github.com/CLDMV/wol-proxy/pull/21)) + +- `.github/dependabot.yml` gains groups that keep `vitest` and `@vitest/*` bumping together (they peer each other exactly, so a partial bump breaks `npm ci`). The same change adds an `eslint` family group (`eslint`, `@eslint/*`, `@cldmv/eslint-plugin-*`) and a `prettier` family group (`prettier`, `@cldmv/prettier-plugin-*`). + +--- + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.0.6.md](./v1.0.6.md) — this changelog (added retroactively). + +--- + +## Upgrade notes + +- No breaking changes — drop-in for v1.0.5. +- No runtime source changed. Running the repo's tests locally now needs Node 22.12.0 or newer because of Vitest 5; the published CLI has no such requirement from this release. diff --git a/docs/changelog/v1/v1.0.7.md b/docs/changelog/v1/v1.0.7.md new file mode 100644 index 0000000..fb11725 --- /dev/null +++ b/docs/changelog/v1/v1.0.7.md @@ -0,0 +1,52 @@ +# wol-proxy v1.0.7 Changelog + +**Release Date**: October 2026 +**Release Type**: Patch + +--- + +## Overview + +A large tooling release: the workflow set is synced to the CLDMV/.github v4.29.2 templates, the shared CLDMV file-header config is adopted, and the Vitest 5 packages move to 5.0.2. The release PR was [#24](https://github.com/CLDMV/wol-proxy/pull/24), titled for a `@vitest/coverage-v8` bump but carrying all of the changes below. + +No runtime behavior changed. `index.js` and `postinstall.js` gain a comment header block only; `wol-proxy.service` and the README are untouched. The runtime part of the lockfile is identical to [v1.0.6](./v1.0.6.md). + +--- + +## 🔧 CI & tooling + +### Sync with the v4.29.2 workflow templates ([#25](https://github.com/CLDMV/wol-proxy/pull/25)) + +- All workflow callers are refreshed and reformatted (four-space indentation). +- New workflows: `member-auto-merge.yml` (enables auto-merge on org members' PRs into `next` / `hotfixes`; it does not approve), `pr-notify.yml` (one notification when a PR opens), `provenance.yml` (SLSA provenance on release), `release-merge.yml` (merges the green, approved release PR), `dependabot-recreate.yml`, and `bundle-size.yml`. +- `bundle-size.yml` runs `npm run build:ci` (still a placeholder echo) and measures `*.js` files on PRs to `master` / `main`. +- `ci.yml` and `publish.yml` now leave `max_node_major` blank so the reusable workflow's default applies, and `publish.yml` declares read-only `contents` permissions. +- `.github/dependabot.yml` comments are updated. + +### Shared file-header config ([#27](https://github.com/CLDMV/wol-proxy/pull/27)) + +- Adds `.configs/fix-headers.json` (extends `@cldmv/configs/fix-headers.json`) and a `fix:headers` script that runs `fix-headers` with it. +- Stamps a uniform comment header (`@Project`, `@Filename`, `@Date`, `@Author`, `@Copyright`) onto source, test, config and workflow files. These are comment-only changes. + +--- + +## 🔧 Dependencies + +All dev dependencies; only the repo's test and CI toolchain is affected. + +- `@cldmv/fix-headers` ^2.1.1 and `@cldmv/configs` ^1.2.0 are added to `devDependencies` (with [#27](https://github.com/CLDMV/wol-proxy/pull/27)). +- `vitest` and `@vitest/coverage-v8` move from 5.0.0 to 5.0.2 in the lockfile, via [#22](https://github.com/CLDMV/wol-proxy/pull/22), [#23](https://github.com/CLDMV/wol-proxy/pull/23), [#28](https://github.com/CLDMV/wol-proxy/pull/28) and [#29](https://github.com/CLDMV/wol-proxy/pull/29) (5.0.0 to 5.0.1 to 5.0.2). The `package.json` ranges stay `^5.0.0`. +- `rolldown` 1.2.8 to 1.2.11, `vite` 8.3.0 to 8.3.1, and smaller transitive bumps. + +--- + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.0.7.md](./v1.0.7.md) — this changelog (added retroactively). + +--- + +## Upgrade notes + +- No breaking changes — drop-in for v1.0.6. +- No runtime code changed; `index.js` and `postinstall.js` have comment headers only. diff --git a/docs/changelog/v1/v1.0.8.md b/docs/changelog/v1/v1.0.8.md new file mode 100644 index 0000000..82f5825 --- /dev/null +++ b/docs/changelog/v1/v1.0.8.md @@ -0,0 +1,35 @@ +# wol-proxy v1.0.8 Changelog + +**Release Date**: October 2026 +**Release Type**: Patch + +--- + +## Overview + +CI-only release that closes a loophole in the `Required PR Check` gate. The release PR was [#32](https://github.com/CLDMV/wol-proxy/pull/32), carrying [#31](https://github.com/CLDMV/wol-proxy/pull/31). + +No runtime code changed and the lockfile differs from [v1.0.7](./v1.0.7.md) only in the package version. The diff is limited to `.github/workflows/ci.yml` and the version in `package.json`. + +--- + +## 🔧 CI & tooling + +### Stop the skipped PR-run mirror from satisfying Required PR Check ([#31](https://github.com/CLDMV/wol-proxy/pull/31)) + +- On an in-repo feature PR, the `pull_request` run skipped the `✅ Required PR Check` mirror job because the push run owns the status. GitHub treats a skipped required check as passing, so a PR could become mergeable, or have auto-merge enabled, before the push run's tests had finished (see [CLDMV/slothlet#553](https://github.com/CLDMV/slothlet/issues/553)). +- The job's `name:` is now an expression, so the skipped job no longer reports under the required name. Paths that actually run still report `✅ Required PR Check`. +- Follow-up in [v1.0.9](./v1.0.9.md): GitHub does not evaluate the `name:` of a skipped job, so the skipped job showed the raw expression text. + +--- + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.0.8.md](./v1.0.8.md) — this changelog (added retroactively). + +--- + +## Upgrade notes + +- No breaking changes — drop-in for v1.0.7. +- No runtime code changed. diff --git a/docs/changelog/v1/v1.0.9.md b/docs/changelog/v1/v1.0.9.md new file mode 100644 index 0000000..4c51f59 --- /dev/null +++ b/docs/changelog/v1/v1.0.9.md @@ -0,0 +1,35 @@ +# wol-proxy v1.0.9 Changelog + +**Release Date**: October 2026 +**Release Type**: Patch + +--- + +## Overview + +CI-only follow-up to [v1.0.8](./v1.0.8.md): the in-repo PR mirror job now runs instead of being skipped. The release PR was [#34](https://github.com/CLDMV/wol-proxy/pull/34), carrying [#33](https://github.com/CLDMV/wol-proxy/pull/33). + +No runtime code changed and the lockfile differs from v1.0.8 only in the package version. The diff is limited to `.github/workflows/ci.yml` and the version in `package.json`. + +--- + +## 🔧 CI & tooling + +### Run the in-repo PR mirror job instead of skipping it ([#33](https://github.com/CLDMV/wol-proxy/pull/33)) + +- v1.0.8 renamed the skipped `Required PR Check` mirror job with an expression, but GitHub does not evaluate the `name:` of a skipped job, so it appeared with the raw expression text. +- The job now uses `if: always()` and never skips. On the in-repo PR path it reports as `⏭️ Required PR Check (reported by the push run)` and exits as a no-op; every path that owns the status (push events, fork PRs, and PRs from `next` / `hotfixes`) still reports `✅ Required PR Check`. +- `needs: ci` is kept, so the required check only appears after the full test matrix for that SHA has finished, and the mirror can still report red when `ci` fails. + +--- + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.0.9.md](./v1.0.9.md) — this changelog (added retroactively). + +--- + +## Upgrade notes + +- No breaking changes — drop-in for v1.0.8. +- No runtime code changed. From a220d4d25126395bbe219ccae4e90899404ce5b7 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 3 Oct 2026 20:44:48 -0700 Subject: [PATCH 4/9] docs: add v1.0.10 changelog and README What's New --- README.md | 16 ++++++++++++++++ docs/changelog/v1/v1.0.10.md | 30 ++++++++++++++++++++++++++++++ 2 files changed, 46 insertions(+) create mode 100644 docs/changelog/v1/v1.0.10.md diff --git a/README.md b/README.md index 5059d63..026902d 100644 --- a/README.md +++ b/README.md @@ -4,6 +4,22 @@ Use it as a local utility or run it on a remote VM to expose WoL via an HTTP API. +## ✨ What's New + +### Latest: v1.0.10 (October 2026) + +- **Dev-tooling dependency bump ([#35](https://github.com/CLDMV/wol-proxy/pull/35))** — `@cldmv/fix-headers` moves from 2.1.1 to 2.1.4, the tool that maintains the repository's file headers. It produced no header changes here, so only `package.json` and the lockfile changed. The Express server and `postinstall.js` are unchanged; it's a drop-in replacement for the previous version. +- [View full v1.0.10 Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.10.md) + +### Recent Releases + +- **v1.0.9** (October 2026) — CI only: the in-repo PR mirror job now always runs and reports under a non-required name instead of being skipped ([Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.9.md)) +- **v1.0.8** (October 2026) — CI only: a skipped PR-run mirror job no longer satisfies the `✅ Required PR Check` ruleset gate ([Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.8.md)) +- **v1.0.7** (October 2026) — workflows synced to the CLDMV/.github v4.29.2 templates, shared fix-headers config (comment-only headers in `index.js` and `postinstall.js`), vitest 5.0.2; no runtime change ([Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.7.md)) +- **v1.0.6** (September 2026) — vitest 5 test toolchain and a CI Node matrix of 22.12.0–26; Express's transitive `qs` moves to 6.16.0 in the lockfile ([Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.6.md)) + +📚 **For complete version history and detailed release notes, see the [docs/changelog/](https://github.com/CLDMV/wol-proxy/tree/master/docs/changelog/) folder.** + --- ## 📦 Installation diff --git a/docs/changelog/v1/v1.0.10.md b/docs/changelog/v1/v1.0.10.md new file mode 100644 index 0000000..b093703 --- /dev/null +++ b/docs/changelog/v1/v1.0.10.md @@ -0,0 +1,30 @@ +# wol-proxy v1.0.10 Changelog + +**Release Date**: October 2026 +**Release Type**: Patch +**Branch**: `next` → `master` + +--- + +## Overview + +A single dev-tooling dependency patch. `@cldmv/fix-headers`, which maintains the comment headers at the top of the repository's source, test, config and workflow files, moves from 2.1.1 to 2.1.4. No runtime code changed: `index.js`, `postinstall.js` and `wol-proxy.service` are exactly as in v1.0.9, and the runtime dependency ranges (`express` ^5.1.0, `wake_on_lan` ^1.0.0) and their lockfile entries are unchanged. + +The bump was made with a header restamp in mind, but fix-headers 2.1.4 produced no header changes in this repository, so the only files touched are `package.json` and `package-lock.json`. + +--- + +## 🔧 Dependencies + +- **`@cldmv/fix-headers` `2.1.1` → `2.1.4`** ([#35](https://github.com/CLDMV/wol-proxy/pull/35)), dev dependency. The 2.1.x line no longer stamps a header into files that have no usable comment syntax (strict JSON such as `package.json`, and Markdown unless explicitly forced), never walks into `node_modules` or other dependency folders, and processes every repeated `--input` value instead of only the last. It only runs through the `fix:headers` script; nothing that ships depends on it. + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.0.10.md](./v1.0.10.md) — this changelog. +- Changelogs for earlier releases that shipped without one were added in the same pass (see the [docs/changelog/](https://github.com/CLDMV/wol-proxy/tree/master/docs/changelog/) folder). + +--- + +## Upgrade notes + +- No breaking changes, and no runtime code changed. It's a drop-in replacement for v1.0.9. From 9266f3d4e7a0076736e123204334fe8e7efdb4e3 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 3 Oct 2026 20:53:17 -0700 Subject: [PATCH 5/9] deps: bump @cldmv/vitest-runner to 1.5.3 Re-applies the vitest-runner bump from #30, which merged into next right after a release and was wiped by the next reset (CLDMV/.github#360). Installed at latest (1.5.3) rather than the original 1.5.1. --- package-lock.json | 22 +++++++++++----------- package.json | 2 +- 2 files changed, 12 insertions(+), 12 deletions(-) diff --git a/package-lock.json b/package-lock.json index c3cc54b..1db405b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -19,7 +19,7 @@ "devDependencies": { "@cldmv/configs": "^1.2.0", "@cldmv/fix-headers": "^2.1.4", - "@cldmv/vitest-runner": "^1.2.0", + "@cldmv/vitest-runner": "^1.5.3", "@vitest/coverage-v8": "^5.0.0", "vitest": "^5.0.0" } @@ -116,19 +116,19 @@ } }, "node_modules/@cldmv/vitest-runner": { - "version": "1.2.0", - "resolved": "https://registry.npmjs.org/@cldmv/vitest-runner/-/vitest-runner-1.2.0.tgz", - "integrity": "sha512-RhmXwFNB68OsgnIFSoQeTWgqEAZt/A+MYfc9lf2JdCUIRhzq2Z3gVeuw1pYOV0LihqfPWRNSmaVVDEEQKa93Tw==", + "version": "1.5.3", + "resolved": "https://registry.npmjs.org/@cldmv/vitest-runner/-/vitest-runner-1.5.3.tgz", + "integrity": "sha512-99+r+7ricaaCjLSYaRzE9d4Ab/NAG6Vgu8fNpGdep9n+DAi98NH//iHsdQjw9yaVh2IXvp37IBRKR8VTETbyZg==", "dev": true, - "license": "MIT", + "license": "Apache-2.0", "dependencies": { - "chalk": "^5.4.1" + "chalk": "^6.0.1" }, "bin": { "vitest-runner": "bin/vitest-runner.mjs" }, "engines": { - "node": ">=20.19.0" + "node": ">=22.12.0" }, "peerDependencies": { "vitest": ">=1.0.0" @@ -705,13 +705,13 @@ } }, "node_modules/chalk": { - "version": "5.6.2", - "resolved": "https://registry.npmjs.org/chalk/-/chalk-5.6.2.tgz", - "integrity": "sha512-7NzBL0rN6fMUW+f7A6Io4h40qQlG+xGmtMxfbnH/K7TAtt8JQWVQK+6g0UXKMeVJoyV5EkkNsErQ8pVD3bLHbA==", + "version": "6.0.1", + "resolved": "https://registry.npmjs.org/chalk/-/chalk-6.0.1.tgz", + "integrity": "sha512-/Ce6KNm3vIbWdMlNna6RVIZ/ICQxnJxCicet5LBKK9ZffBkqzDw0xh9EiKSljdRtiIQ1S1z4YgcscUUGzNCWrA==", "dev": true, "license": "MIT", "engines": { - "node": "^12.17.0 || ^14.13 || >=16.0.0" + "node": ">=22" }, "funding": { "url": "https://github.com/chalk/chalk?sponsor=1" diff --git a/package.json b/package.json index 1d76df0..aa85275 100644 --- a/package.json +++ b/package.json @@ -45,7 +45,7 @@ "devDependencies": { "@cldmv/configs": "^1.2.0", "@cldmv/fix-headers": "^2.1.4", - "@cldmv/vitest-runner": "^1.2.0", + "@cldmv/vitest-runner": "^1.5.3", "@vitest/coverage-v8": "^5.0.0", "vitest": "^5.0.0" } From 7b9e1bde0acfea9dcb2b4c5d4e50bc76c6e31454 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 3 Oct 2026 20:54:32 -0700 Subject: [PATCH 6/9] docs: add the restored vitest-runner bump (#38) to the v1.0.10 notes --- docs/changelog/v1/v1.0.10.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/changelog/v1/v1.0.10.md b/docs/changelog/v1/v1.0.10.md index b093703..58f06e6 100644 --- a/docs/changelog/v1/v1.0.10.md +++ b/docs/changelog/v1/v1.0.10.md @@ -17,6 +17,7 @@ The bump was made with a header restamp in mind, but fix-headers 2.1.4 produced ## 🔧 Dependencies - **`@cldmv/fix-headers` `2.1.1` → `2.1.4`** ([#35](https://github.com/CLDMV/wol-proxy/pull/35)), dev dependency. The 2.1.x line no longer stamps a header into files that have no usable comment syntax (strict JSON such as `package.json`, and Markdown unless explicitly forced), never walks into `node_modules` or other dependency folders, and processes every repeated `--input` value instead of only the last. It only runs through the `fix:headers` script; nothing that ships depends on it. +- **`@cldmv/vitest-runner` `1.2.0` → `1.5.3`** ([#38](https://github.com/CLDMV/wol-proxy/pull/38)), dev dependency (the test runner). This restores the bump from [#30](https://github.com/CLDMV/wol-proxy/pull/30), which merged into `next` just after the previous release and was dropped by the post-release reset of `next` ([CLDMV/.github#360](https://github.com/CLDMV/.github/issues/360)); it is reinstalled at the latest version instead of the original 1.5.1. Test tooling only; nothing that ships depends on it. ## 📚 Documentation From 4b226188db2a99ca337cc9329dfe8d85076bade9 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 4 Oct 2026 16:38:41 -0700 Subject: [PATCH 7/9] deps: bump @cldmv/fix-headers to 2.2.0 Bumps @cldmv/fix-headers from 2.1.4 to 2.2.0. No file headers changed. --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index 1db405b..9f6f690 100644 --- a/package-lock.json +++ b/package-lock.json @@ -18,7 +18,7 @@ }, "devDependencies": { "@cldmv/configs": "^1.2.0", - "@cldmv/fix-headers": "^2.1.4", + "@cldmv/fix-headers": "^2.2.0", "@cldmv/vitest-runner": "^1.5.3", "@vitest/coverage-v8": "^5.0.0", "vitest": "^5.0.0" @@ -96,9 +96,9 @@ } }, "node_modules/@cldmv/fix-headers": { - "version": "2.1.4", - "resolved": "https://registry.npmjs.org/@cldmv/fix-headers/-/fix-headers-2.1.4.tgz", - "integrity": "sha512-PvCKMztN9k+jOjEpMCANMaDIkNW7cs2qp5P73JVzResk1+DfqhoZVqT9jpTT8cUu+6OGszsNqj8/X0Q9IhfNtg==", + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/@cldmv/fix-headers/-/fix-headers-2.2.0.tgz", + "integrity": "sha512-EQTAKCo0B639q2bde+vO5ciYbtvNgAJFm0DBthIJQnmTFJmQDUlObp5EsTRgg5CUlFoUnGMX+q35LC02QvYU4w==", "dev": true, "license": "Apache-2.0", "dependencies": { diff --git a/package.json b/package.json index aa85275..c7e4b97 100644 --- a/package.json +++ b/package.json @@ -44,7 +44,7 @@ }, "devDependencies": { "@cldmv/configs": "^1.2.0", - "@cldmv/fix-headers": "^2.1.4", + "@cldmv/fix-headers": "^2.2.0", "@cldmv/vitest-runner": "^1.5.3", "@vitest/coverage-v8": "^5.0.0", "vitest": "^5.0.0" From f2c9d6a61465ae2ab23087aa81b822eeafb9665e Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 4 Oct 2026 19:08:50 -0700 Subject: [PATCH 8/9] deps: bump @cldmv/configs to 1.2.4 Raises the range from ^1.2.0 (locked 1.2.0) to ^1.2.4. Configs 1.2.4 sets forceAuthorUpdate and forceLastModifiedAuthorUpdate to false, so with fix-headers 2.2.0 @Author is never rewritten and @Last modified by changes only on real content edits. Ran fix:headers under the new config: 0 files restamped. --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index 9f6f690..b44e088 100644 --- a/package-lock.json +++ b/package-lock.json @@ -17,7 +17,7 @@ "wol-proxy": "index.js" }, "devDependencies": { - "@cldmv/configs": "^1.2.0", + "@cldmv/configs": "^1.2.4", "@cldmv/fix-headers": "^2.2.0", "@cldmv/vitest-runner": "^1.5.3", "@vitest/coverage-v8": "^5.0.0", @@ -85,9 +85,9 @@ } }, "node_modules/@cldmv/configs": { - "version": "1.2.0", - "resolved": "https://registry.npmjs.org/@cldmv/configs/-/configs-1.2.0.tgz", - "integrity": "sha512-FDmlxOx6ceKuD5zTamUy9XOfAC4opeOaLxWqZz9okKxj8TsTZP6dN7W0VccRYRdw4606NvXjhdZqOPibcNpXmQ==", + "version": "1.2.4", + "resolved": "https://registry.npmjs.org/@cldmv/configs/-/configs-1.2.4.tgz", + "integrity": "sha512-7HPqAgCKqol3fHpawEsXJ5ZqHxlDPZk1puoFu43f/gaNfhWwufDTzjkvLk90yVEumyz4N3pUwIxfbHUkUTpDEg==", "dev": true, "license": "Apache-2.0", "funding": { diff --git a/package.json b/package.json index c7e4b97..6136724 100644 --- a/package.json +++ b/package.json @@ -43,7 +43,7 @@ "wake_on_lan": "^1.0.0" }, "devDependencies": { - "@cldmv/configs": "^1.2.0", + "@cldmv/configs": "^1.2.4", "@cldmv/fix-headers": "^2.2.0", "@cldmv/vitest-runner": "^1.5.3", "@vitest/coverage-v8": "^5.0.0", From e9aff7e54d8057328cf8d97363f94e1c7e602ba3 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sun, 4 Oct 2026 20:06:59 -0700 Subject: [PATCH 9/9] docs: update the v1.0.10 release notes --- README.md | 2 +- docs/changelog/v1/v1.0.10.md | 11 +++++++---- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 026902d..22f0af8 100644 --- a/README.md +++ b/README.md @@ -8,7 +8,7 @@ Use it as a local utility or run it on a remote VM to expose WoL via an HTTP API ### Latest: v1.0.10 (October 2026) -- **Dev-tooling dependency bump ([#35](https://github.com/CLDMV/wol-proxy/pull/35))** — `@cldmv/fix-headers` moves from 2.1.1 to 2.1.4, the tool that maintains the repository's file headers. It produced no header changes here, so only `package.json` and the lockfile changed. The Express server and `postinstall.js` are unchanged; it's a drop-in replacement for the previous version. +- **Dev-tooling dependency bumps ([#35](https://github.com/CLDMV/wol-proxy/pull/35), [#38](https://github.com/CLDMV/wol-proxy/pull/38), [#40](https://github.com/CLDMV/wol-proxy/pull/40))** — `@cldmv/fix-headers` moves to 2.2.0, `@cldmv/configs` to 1.2.4 and `@cldmv/vitest-runner` to 1.5.3. No file headers changed and no runtime code changed: the Express server and `postinstall.js` are as in the previous version, so it's a drop-in replacement. - [View full v1.0.10 Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.10.md) ### Recent Releases diff --git a/docs/changelog/v1/v1.0.10.md b/docs/changelog/v1/v1.0.10.md index 58f06e6..cb8a62d 100644 --- a/docs/changelog/v1/v1.0.10.md +++ b/docs/changelog/v1/v1.0.10.md @@ -8,16 +8,19 @@ ## Overview -A single dev-tooling dependency patch. `@cldmv/fix-headers`, which maintains the comment headers at the top of the repository's source, test, config and workflow files, moves from 2.1.1 to 2.1.4. No runtime code changed: `index.js`, `postinstall.js` and `wol-proxy.service` are exactly as in v1.0.9, and the runtime dependency ranges (`express` ^5.1.0, `wake_on_lan` ^1.0.0) and their lockfile entries are unchanged. +A dev-tooling dependency release. Three development dependencies move forward: `@cldmv/fix-headers`, which maintains the comment headers at the top of the repository's source, test, config and workflow files (2.1.1 to 2.2.0), `@cldmv/configs`, the shared lint, format and header configuration (1.2.0 to 1.2.4), and `@cldmv/vitest-runner`, the test runner (1.2.0 to 1.5.3). -The bump was made with a header restamp in mind, but fix-headers 2.1.4 produced no header changes in this repository, so the only files touched are `package.json` and `package-lock.json`. +No runtime code changed: `index.js`, `postinstall.js` and `wol-proxy.service` are exactly as in v1.0.9, and the runtime dependency ranges (`express` `^5.1.0`, `wake_on_lan` `^1.0.0`) and their lockfile entries are unchanged. The only other lockfile movement is `chalk` 5.6.2 to 6.0.1, a dev-only dependency of the test runner. No file headers were restamped by either fix-headers step, so the files touched are `package.json`, `package-lock.json` and the documentation. --- ## 🔧 Dependencies -- **`@cldmv/fix-headers` `2.1.1` → `2.1.4`** ([#35](https://github.com/CLDMV/wol-proxy/pull/35)), dev dependency. The 2.1.x line no longer stamps a header into files that have no usable comment syntax (strict JSON such as `package.json`, and Markdown unless explicitly forced), never walks into `node_modules` or other dependency folders, and processes every repeated `--input` value instead of only the last. It only runs through the `fix:headers` script; nothing that ships depends on it. -- **`@cldmv/vitest-runner` `1.2.0` → `1.5.3`** ([#38](https://github.com/CLDMV/wol-proxy/pull/38)), dev dependency (the test runner). This restores the bump from [#30](https://github.com/CLDMV/wol-proxy/pull/30), which merged into `next` just after the previous release and was dropped by the post-release reset of `next` ([CLDMV/.github#360](https://github.com/CLDMV/.github/issues/360)); it is reinstalled at the latest version instead of the original 1.5.1. Test tooling only; nothing that ships depends on it. +All dev-only; nothing that ships depends on them. + +- **`@cldmv/fix-headers` `^2.1.1` → `^2.2.0`** (locked 2.1.1 to 2.2.0), in two steps: 2.1.4 ([#35](https://github.com/CLDMV/wol-proxy/pull/35)) and 2.2.0 ([#40](https://github.com/CLDMV/wol-proxy/pull/40)). The 2.1.x line no longer stamps a header into files that have no usable comment syntax (strict JSON such as `package.json`, and Markdown unless explicitly forced), never walks into `node_modules` or other dependency folders, and processes every repeated `--input` value instead of only the last. From 2.2.0 the `@Last modified by` tag follows content edits only, so a header-only rewrite keeps the recorded editor. It only runs through the `fix:headers` script. Neither step changed any header in this repository. +- **`@cldmv/configs` `^1.2.0` → `^1.2.4`** (locked 1.2.0 to 1.2.4) ([#40](https://github.com/CLDMV/wol-proxy/pull/40)). Version 1.2.4 sets `forceAuthorUpdate` and `forceLastModifiedAuthorUpdate` to `false`, so `@Author` is never rewritten and `@Last modified by` changes only on real content edits. Re-running `fix:headers` under the new config restamped no files. +- **`@cldmv/vitest-runner` `^1.2.0` → `^1.5.3`** (locked 1.2.0 to 1.5.3) ([#38](https://github.com/CLDMV/wol-proxy/pull/38)). This restores the bump from [#30](https://github.com/CLDMV/wol-proxy/pull/30), which merged into `next` just after the previous release and was dropped by the post-release reset of `next` ([CLDMV/.github#360](https://github.com/CLDMV/.github/issues/360)); it is reinstalled at the latest version instead of the original 1.5.1. The runner's own `chalk` dependency moves from `^5.4.1` to `^6.0.1` (locked 5.6.2 to 6.0.1), which requires Node 22 or newer; the CI matrix already starts at 22.12.0. ## 📚 Documentation