Skip to content

chore: promote nightly to main (2026-10-05) - #134

Merged
Wikid82 merged 17 commits into
mainfrom
nightly
Oct 5, 2026
Merged

Wikid82 merged 17 commits into
mainfrom
nightly

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Promote nightly to main

Date: 2026-10-05
Trigger: Scheduled weekly promotion
CI on nightly HEAD: https://github.com/Wikid82/Hestia/actions/runs/37113219934

Commits being promoted

d656a6d chore: update anchore/sbom-action action to v0.24.3 (#132)
3f406ca chore: update anchore/sbom-action action to v0.24.3
34546fb chore(deps): install npm deps in the correct package and sections
0e112c5 chore(deps): bump @types/node, vite, and lefthook
cf5568c chore(deps): bump globals to 17.13.0 and add update script
796a812 chore(deps): bump vitest to 5.0.3 and refresh lockfiles
7c5a56b fix(scripts): prefer upgraded global npm on PATH after self-update
77208a3 chore(deps): update npm lockfile dependencies
064da2d chore(deps): update indirect Go dependencies in backend
acfc427 refactor: simplify update_go function and improve usage message
7cc853c refactor(frontend): clear react-refresh eslint warnings
29d6016 fix: clear lint, semgrep, actionlint and hadolint findings
39d6ffb chore: mirror Charon's lefthook setup and untrack root node_modules
4ccff55 chore(frontend): bump typescript-eslint to 8.71.0 and refresh deps
1e5b701 chore: propagate main into development (#130)

Merge instructions — important

Use "Create a merge commit", not squash or rebase. Squashing collapses every
feat:/fix: commit into one bullet-list body, which release-please can't parse —
version bumps and changelog entries silently stop working.


Opened automatically by Promote nightly to main.

Wikid82 and others added 17 commits September 28, 2026 07:19
Add explicit @typescript-eslint/eslint-plugin, parser and utils dev
dependencies alongside typescript-eslint, and add a helper script to
update them together. Regenerate package-lock.json, which also picks up
minor transitive updates (rolldown, csstools, browserslist, undici).
- lefthook.yml: pre-commit adds file hygiene, commit guards, shellcheck,
  actionlint and semgrep; manual security-full, codeql, testing and
  lint-full pipelines; pre-push build+test is kept.
- scripts/pre-commit-hooks: ported guards, gitleaks, semgrep and CodeQL
  scan wrappers; markdownlint/hadolint configs.
- Root node_modules (lefthook binary) was committed by accident; untrack
  it and gitignore it. Bump lefthook to 2.1.15 and track scripts/npm/root.
- dep-update script now covers the root package; golangci bodyclose is
  excluded for test helpers that already close response bodies.
- CLAUDE.md: CI/workflow changes now go through normal PRs to development.
- mailer: set MinVersion TLS 1.2 on the SMTP TLS config (same effective
  minimum as Go's default, now explicit); check-close errors handled.
- database: create the DB directory with 0750 instead of 0755.
- Dockerfile: WORKDIR instead of cd, numeric USER 1000:1000.
- workflows: quote/array-ify the buildx manifest command, use find instead
  of ls, unused loop var in the e2e health wait.
- golangci: shadowed err, unnamed results, redundant route blocks,
  unchecked Close in the websocket hub.
- docs: markdownlint fixes (fence spacing/languages, FAQ heading levels).
- Move useAuth/AuthContext into context/useAuth.ts so AuthContext.tsx
  only exports the AuthProvider component.
- Move ChoreFieldsValue/defaultChoreFieldsValue into
  components/choreFieldsValue.ts so ChoreFields.tsx only exports a
  component.
- Turn off react-refresh/only-export-components for src/test/**; test
  helpers aren't part of the app bundle.
Bump go-json to v0.11.2, go-strftime to v1.1.0, modernc.org/sqlite
to v1.60.1, libc to v1.77.1, ccgo to v4.36.1, and go-playground/locales
to v0.14.2.
Refresh transitive dependencies in docs-site and frontend lockfiles
(swc, memfs/jsonjoy, peculiar asn1, micromark, browserslist, etc.).
Add the package name to the root package-lock.json.
After `npm install -g npm@latest`, put the global prefix bin dir first
on PATH and rehash, so the upgraded npm is used instead of the Node
manager's bundled copy (fnm/nvm). Log the active npm version and path.
Update frontend vitest, @vitest/coverage-istanbul, coverage-v8 and ui
to ^5.0.3. Refresh frontend and docs-site lockfiles with transitive
updates: @swc/core and @swc/html 1.16.13, rolldown 1.2.12,
caniuse-lite, electron-to-chromium, cssdb, source-map-js, ignore and
tinyrainbow.
Update globals to ^17.13.0 in frontend and add it as a dev dependency
in docs-site. Add scripts/npm/globals.sh to update the package across
both npm modules.
Update dependency patch versions across the workspace:
- @types/node 26.6.3 -> 26.6.4 (frontend, docs-site)
- vite 8.3.1 -> 8.3.2 (frontend)
- lefthook 2.1.15 -> 2.1.16 (root)

Lockfiles also pick up transitive updates such as chai,
follow-redirects, and algoliasearch-helper.
Remove unused eslint/globals from docs-site, move frontend-only update
scripts under scripts/npm/frontend, pass explicit --save-dev/--save-prod
flags, and fix the serialize-javascript override check.
@codecov-commenter

Copy link
Copy Markdown

@Wikid82
Wikid82 merged commit e70668e into main Oct 5, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants