Conversation
Add a small package for per-process secrets and local address checks, and share the management network helper.
Tighten validation in a few API handlers and surface persistence errors.
Add an engine-wide middleware chain constructor and a request context record used by the auth helpers.
Pass request context details between the proxy and the API for routes that target the API itself.
Tighten credential handling and session lifecycle in the authentication service and user handlers, with accompanying tests.
Read caller identity through shared accessors and tighten request validation. Adds guard and regression tests.
Rebuilds the prebuilt Caddy/CrowdSec toolchain image so the shipped binaries pick up upstream fixes, and bumps the digest pin in the Dockerfile.
Give the bundled PowerDNS plugin its own module entry in the repository workspace so it is compiled and tested alongside the backend with identical dependency versions. This adds a make target and CI step that build the plugin (CGO enabled, same toolchain and flags as the host binary: no trimpath, race or cover) and a plugin.Open smoke test that always rebuilds the plugin into a temporary directory. The new manifest lives in the existing plugin directory and only imports the public backend packages; no backend code is copied or moved. The Renovate config is updated accordingly. No behaviour change.
Introduce a small public helper package for plugins and in-tree providers that need to make outbound HTTP requests to administrator-configured endpoints, and consolidate the address-policy checks in the internal network package behind a single predicate. Policy rejections now carry a stable sentinel error that omits resolved addresses, and optional range-blocking client options are added (off by default). Foundation for the following commits, which add the first callers; no behaviour change.
Add a go get step for github.com/jackc/pgproto3/v2@v2.3.3 before go mod tidy to address CVE-2026-32286, a buffer overflow in pgproto3/v2. The bundled crowdsec and cscli binaries otherwise resolve to a vulnerable version via MVS.
Rebuilds the prebuilt Caddy/CrowdSec toolchain image so the shipped binaries pick up upstream fixes, and bumps the digest pin in the Dockerfile.
Automated checksum update for GeoLite2-Country.mmdb database. Old: aa10ad6c6dc7daa32344954a9bdfae83d8e791540b7d17f7d06086aeb5b630cc New: ff539785596f72ac2a07048f08506b38134bcf3b568182fd65f4534817bf91d7 Auto-generated by: .github/workflows/update-geolite2.yml
…w_run against forks
Update the docs-site npm override and lockfile to http-cache-semantics 4.3.0. Add scripts/npm/docs-site/http-cache-semantics.sh to automate the bump. It refuses to add an override that is not already declared and preserves the existing range prefix.
Pin the transitive `feed` dependency to ^6.0.0 via npm overrides and refresh the lockfile. Add scripts/npm/docs-site/feed.sh to bump the override to the latest release, refusing to run in modules that don't already declare it.
Codecov Report❌ Patch coverage is 📢 Thoughts on this report? Let us know! |
Contributor
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Contributor
Author
✅ Supply Chain Verification Results✅ PASSED 📦 SBOM Summary
🔍 Vulnerability Scan
📎 Artifacts
Generated by Supply Chain Verification workflow • View Details |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚀 Nightly to Main Promotion
Date: 2026-10-05
Trigger: Scheduled weekly promotion
Commits: 70 commits to promote
Changes: 171 files changed, 8750 insertions(+), 1287 deletions(-)
Commits Being Promoted
Showing first 50 of 70 commits:
...and 20 more commits
Pre-Merge Checklist
Once all checks pass:
This PR was automatically created by the Weekly Nightly Promotion workflow.