Skip to content

build(deps): bump the github-actions group across 1 directory with 5 updates - #2

Closed
dependabot[bot] wants to merge 43 commits into
mainfrom
dependabot/github_actions/github-actions-4ef91543cb
Closed

dependabot[bot] wants to merge 43 commits into
mainfrom
dependabot/github_actions/github-actions-4ef91543cb

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 18, 2026 •

Copy link
Copy Markdown

Bumps the github-actions group with 5 updates in the / directory:

Package From To
actions/checkout 4 7
docker/setup-buildx-action 3 4
docker/build-push-action 6 7
docker/metadata-action 5 6
docker/login-action 3 4

Updates actions/checkout from 4 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

v6.0.0

What's Changed

... (truncated)

Commits

Updates docker/setup-buildx-action from 3 to 4

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.0.0

Full Changelog: docker/setup-buildx-action@v3.12.0...v4.0.0

v3.12.0

Full Changelog: docker/setup-buildx-action@v3.11.1...v3.12.0

v3.11.1

Full Changelog: docker/setup-buildx-action@v3.11.0...v3.11.1

v3.11.0

Full Changelog: docker/setup-buildx-action@v3.10.0...v3.11.0

v3.10.0

Full Changelog: docker/setup-buildx-action@v3.9.0...v3.10.0

v3.9.0

Full Changelog: docker/setup-buildx-action@v3.8.0...v3.9.0

v3.8.0

Full Changelog: docker/setup-buildx-action@v3.7.1...v3.8.0

... (truncated)

Commits
  • d7f5e7f Merge pull request #489 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 92bc5c9 chore: update generated content
  • da11e35 build(deps): bump @​docker/actions-toolkit from 0.79.0 to 0.90.0
  • f021e16 Merge pull request #492 from docker/dependabot/npm_and_yarn/undici-6.24.1
  • b5af94f chore: update generated content
  • 16ad977 build(deps): bump undici from 6.23.0 to 6.25.0
  • d7a12d7 Merge pull request #495 from docker/dependabot/npm_and_yarn/glob-10.5.0
  • 28ff27d build(deps): bump glob from 10.3.12 to 13.0.6
  • daf436b Merge pull request #496 from docker/dependabot/npm_and_yarn/fast-xml-parser-5...
  • 9725348 chore: update generated content
  • Additional commits viewable in compare view

Updates docker/build-push-action from 6 to 7

Release notes

Sourced from docker/build-push-action's releases.

v7.0.0

Full Changelog: docker/build-push-action@v6.19.2...v7.0.0

v6.19.2

Full Changelog: docker/build-push-action@v6.19.1...v6.19.2

v6.19.1

Full Changelog: docker/build-push-action@v6.19.0...v6.19.1

v6.19.0

Full Changelog: docker/build-push-action@v6.18.0...v6.19.0

v6.18.0

[!NOTE] Build summary is now supported with Docker Build Cloud.

Full Changelog: docker/build-push-action@v6.17.0...v6.18.0

v6.17.0

[!NOTE] Build record is now exported using the buildx history export command instead of the legacy export-build tool.

Full Changelog: docker/build-push-action@v6.16.0...v6.17.0

v6.16.0

... (truncated)

Commits
  • f9f3042 Merge pull request #1517 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 812d5fd chore: update generated content
  • b6f6693 chore(deps): Bump @​docker/actions-toolkit from 0.87.0 to 0.90.0
  • c1c626e Merge pull request #1525 from docker/dependabot/npm_and_yarn/actions/core-3.0.1
  • 51bb284 chore: update generated content
  • 5f7884d chore(deps): Bump @​actions/core from 3.0.0 to 3.0.1
  • e01deff Merge pull request #1521 from docker/dependabot/npm_and_yarn/fast-xml-parser-...
  • 3804d49 chore: update generated content
  • 71e8947 chore(deps): Bump fast-xml-parser from 5.5.7 to 5.8.0
  • 4925ad2 Merge pull request #1526 from docker/dependabot/npm_and_yarn/postcss-8.5.10
  • Additional commits viewable in compare view

Updates docker/metadata-action from 5 to 6

Release notes

Sourced from docker/metadata-action's releases.

v6.0.0

Full Changelog: docker/metadata-action@v5.10.0...v6.0.0

v5.10.0

Full Changelog: docker/metadata-action@v5.9.0...v5.10.0

v5.9.0

Full Changelog: docker/metadata-action@v5.8.0...v5.9.0

v5.8.0

Full Changelog: docker/metadata-action@v5.7.0...v5.8.0

v5.7.0

Full Changelog: docker/metadata-action@v5.6.1...v5.7.0

... (truncated)

Commits
  • 80c7e94 Merge pull request #613 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 8e0ddab chore: update generated content
  • a8db14b chore(deps): Bump @​docker/actions-toolkit from 0.79.0 to 0.90.0
  • 63a7371 Merge pull request #617 from docker/dependabot/npm_and_yarn/csv-parse-6.2.0
  • c6916a6 chore: update generated content
  • aca9205 chore(deps): Bump csv-parse from 6.1.0 to 6.2.1
  • 9dcfe60 Merge pull request #629 from docker/dependabot/npm_and_yarn/handlebars-4.7.9
  • 43dea76 chore: update generated content
  • 7a56f5a chore(deps): Bump handlebars from 4.7.8 to 4.7.9
  • e49e0aa Merge pull request #658 from docker/dependabot/npm_and_yarn/brace-expansion-5...
  • Additional commits viewable in compare view

Updates docker/login-action from 3 to 4

Release notes

Sourced from docker/login-action's releases.

v4.0.0

Full Changelog: docker/login-action@v3.7.0...v4.0.0

v3.7.0

Full Changelog: docker/login-action@v3.6.0...v3.7.0

v3.6.0

Full Changelog: docker/login-action@v3.5.0...v3.6.0

v3.5.0

Full Changelog: docker/login-action@v3.4.0...v3.5.0

v3.4.0

Full Changelog: docker/login-action@v3.3.0...v3.4.0

... (truncated)

Commits
  • 650006c Merge pull request #960 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...
  • 99df1a3 chore: update generated content
  • 3ab375f build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 39d8580 Merge pull request #970 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 4eefcd3 chore: update generated content
  • 56d092c build(deps): bump @​docker/actions-toolkit from 0.86.0 to 0.90.0
  • e2e31ca Merge pull request #976 from docker/dependabot/npm_and_yarn/actions/core-3.0.1
  • 0bced94 chore: update generated content
  • 3e75a0f build(deps): bump @​actions/core from 3.0.0 to 3.0.1
  • 365bebd Merge pull request #984 from docker/dependabot/github_actions/aws-actions/con...
  • Additional commits viewable in compare view

Readest Lite Bot added 5 commits June 18, 2026 14:48
- Database: Supabase Postgres → SQLite + Prisma (14 tables aligned)
- Object storage: R2/S3 → local filesystem + HMAC-signed URLs
- Auth: Supabase GoTrue → local JWT, single admin (ADMIN_EMAIL/ADMIN_PASSWORD)
- Supabase Auth compat shim at /auth/v1/* (frontend supabase-js untouched)
- Sync protocol 1:1 replicated: /api/sync + /api/sync/replicas + /api/sync/replica-keys
- Share protocol 1:1 replicated: 8 endpoints + OG image renderer
- CRDT merge function reimplemented in TS (replaces Postgres PL/pgSQL RPC)
- Storage: /api/storage/* + internal /api/storage/_put and /api/storage/_get
- Send to Readest: 6 endpoints, SQLite-backed (email channel unavailable)
- Pro/paywall completely removed: Stripe + Apple/Google IAP routes deleted
- Signup disabled: returns 403; login page reduced to email/password only
- Frontend business code, sync logic, reader core untouched
- Single Docker image, port 8225, /data volume for SQLite + books + inbox
- CI: build + Docker image build on push

Co-authored-by: Readest Lite Bot
Issues found during project integrity check and fixed:

1. Dockerfile: replaced glob patterns in COPY (Docker COPY doesn't support
   glob) with concrete paths from apps/readest-app/node_modules/

2. docker/entrypoint.sh: fixed prisma CLI invocation path to absolute
   /app/node_modules/prisma/build/index.js

3. utils/supabase.ts: added missing methods on pseudo supabase client
   - updateUser (returns disabled error, used by auth/update/page.tsx)
   - signInWithOAuth (returns disabled error)
   - signInWithIdToken (returns disabled error)

4. app/auth/recovery/page.tsx: simplified — removed @supabase/auth-ui-react
   and @supabase/auth-ui-shared imports; replaced with informational page
   (password recovery is admin-managed in Lite)

5. app/auth/update/page.tsx: simplified — removed supabase.auth.updateUser
   call; replaced with informational page (email is admin-managed in Lite)

6. utils/storage.ts: added 'local' to ObjectStorageType union (was only
   'r2' | 's3'; OBJECT_STORAGE_TYPE=local env var now correctly typed)

7. utils/book.ts: getRemoteBookFilename now treats 'local' same as 'r2'
   (was returning empty string for 'local' type)

Co-authored-by: Readest Lite Bot
Root cause of build failure: packages/foliate-js and packages/simplecc-wasm
are Git submodules (.gitmodules), but Docker build context from GitHub Actions
checkout has these directories empty (submodules: recursive doesn't always
work, especially on forks).

Fix:
- Removed 'COPY packages/ ./packages/' from Dockerfile (it was copying empty
  submodule stubs)
- Added explicit 'git clone --depth 1' for the two submodules actually needed
  by web build (foliate-js as pnpm workspace member + pdfjs vendors;
  simplecc-wasm for dist/web/* used by setup-vendors)
- Other submodules (tauri, tauri-plugins, qcms, js-mdict) are not needed for
  web build and are not cloned
- Added git + ca-certificates to dependencies stage
- Build stage now explicitly copies the cloned packages/foliate-js and
  packages/simplecc-wasm from dependencies stage

CI workflow simplified:
- Removed 'submodules: recursive' from checkout (no longer needed)
- Replaced pnpm build with Docker build smoke test
- Added container startup smoke test: login + settings + signup-disabled

This makes the build self-contained — it works regardless of how the
checkout was performed.
The original nativeDatabaseService.ts imports from 'tauri-plugin-turso' which
is a src-tauri/plugins/ submodule (not an npm package). With src-tauri removed
for the web-only build, this import would break webpack resolution.

Replace with a stub that throws at runtime (only invoked when
isTauriAppPlatform() is true, which is never in web build). TypeScript
satisfies the DatabaseService interface; webpack no longer needs to resolve
the missing module.

Other @tauri-apps/* imports are all npm packages (in dependencies) and
remain untouched. They are tree-shaken out of the web bundle by
next.config.mjs's NEXT_PUBLIC_APP_PLATFORM=web constant.
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 18, 2026
Readest Lite Bot added 21 commits June 18, 2026 22:32
- Add section 8: GitHub Actions deployment (auto build, GHCR push, pull & run)
- Add section 9 (was 8): Security recommendations
- Add section 10 (was 9): Differences from upstream
- Clarify that submodule clone happens inside Dockerfile, not via git clone --recursive
Root cause of CI build failure: pnpm-lock.yaml was not updated when
@prisma/client, argon2, jsonwebtoken, prisma, @types/jsonwebtoken were
added to package.json. With --frozen-lockfile, pnpm refuses to install
because the lockfile doesn't match package.json.

Fix: use --no-frozen-lockfile so pnpm resolves and updates the lockfile
on the fly. Once a maintainer runs 'pnpm install' locally and commits
the updated pnpm-lock.yaml, this can be changed back to --frozen-lockfile
for reproducible builds.
pnpm 11 defaults to skipping build scripts for security. @prisma/client,
@prisma/engines, prisma (CLI), and argon2 (native module) all need to run
their install/postinstall scripts.

Add them to onlyBuiltDependencies in pnpm-workspace.yaml alongside the
existing sharp entry.

This resolves: [ERR_PNPM_IGNORED_BUILDS] Ignored build scripts
onlyBuiltDependencies in pnpm-workspace.yaml was not getting picked up
during the Docker build (pnpm 11 still raises ERR_PNPM_IGNORED_BUILDS).
Add --config.dangerouslyAllowAllBuilds=true to the pnpm install command
to bypass the security gate. This is acceptable for a single-tenant
self-hosted build where the dependency set is fully trusted.

Required by:
- @prisma/client (postinstall generates query engine binary)
- @prisma/engines
- prisma (CLI binary)
- argon2 (native argon2 binding)
Root cause of CI failure: 'pnpm exec prisma generate' was called in the
build stage. Prisma CLI internally runs 'pnpm add prisma@<version> -D' to
auto-install itself if it thinks it's missing, which fails in the build
stage due to network restrictions and pnpm cache state.

Fix:
- Move 'COPY prisma' + 'pnpm exec prisma generate' to the dependencies
  stage (where pnpm cache is fresh and network is available)
- Remove the prisma generate step from build stage entirely; the build
  stage copies node_modules from dependencies stage, which already
  contains the generated @prisma/client code in
  apps/readest-app/node_modules/.prisma/client
Prisma 6.x CLI on 'prisma generate' tries to auto-install itself via
'pnpm add prisma@<version> -D --silent' even when prisma is already in
dependencies. This fails in Docker due to lockfile conflicts.

Setting PRISMA_NO_AUTO_INSTALL=true env var disables this auto-install
behavior.
…rectly

pnpm exec prisma triggers prisma 6.x's auto-install check which calls
'pnpm add prisma@<version> -D --silent' even though prisma is already
installed. This fails in Docker due to lockfile conflicts.

Solution: call the prisma CLI entry point directly via
'node node_modules/prisma/build/index.js generate' — bypassing pnpm exec's
wrapper that triggers the auto-install detection.
Prisma 6.x CLI checks whether 'prisma' is in the current workspace
package's dependencies (not devDependencies). When it's only in
devDependencies, prisma generate triggers 'pnpm add prisma@<version> -D'
auto-install, which fails in Docker.

Moving prisma to dependencies satisfies the check. The package is still
~80MB but that's the cost of prisma 6.x's CLI bundling.

This is the standard workaround documented in prisma issues for
monorepo + Docker setups.
Prisma 6.x introduces an 'auto-install' behavior that calls
'pnpm add prisma@<version> -D --silent' during 'prisma generate', even
when prisma is already installed. This fails in Docker due to lockfile
conflicts and is not disableable via env vars or flags.

Downgrade to Prisma 5.22 (latest stable 5.x), which doesn't have this
behavior. Prisma 5 fully supports our SQLite schema (14 models, Json,
Bytes, BigInt, all @@id/@@unique). No code changes needed — the
@prisma/client API is identical between 5.x and 6.x for our usage.
Prisma 5.x AND 6.x both call 'pnpm add prisma@<version> -D --silent'
during 'prisma generate' even when prisma is already installed. This
fails in Docker due to lockfile conflicts, and there's no env var or
flag to disable it.

Workaround: temporarily replace pnpm with a stub script that exits 0
(no-op), run prisma generate, then restore the real pnpm. This lets
prisma's auto-install check 'succeed' without actually modifying the
installation.

The stub is only active for the single RUN command that calls prisma
generate; subsequent steps use the real pnpm again.
Two build errors fixed:

1. 'Module not found: Can\'t resolve js-mdict'
   - tsconfig.json has path mapping 'js-mdict' -> '../../packages/js-mdict/src/index.ts'
   - packages/js-mdict is a git submodule that was empty in Docker build context
   - Fix: clone js-mdict in Dockerfile alongside foliate-js and simplecc-wasm
   - Also copy packages/js-mdict from dependencies to build stage

2. 'Module not found: Can\'t resolve fs'
   - utils/usage.ts imports prismaClient at module top level
   - prismaClient (PrismaClient) requires 'fs' to read SQLite file
   - When usage.ts is imported from client-side code (deepl.ts),
     Next.js tries to bundle prismaClient and fails on 'fs'
   - Fix: replace 'import { prismaClient } from ./db' with dynamic
     'await import(./db)' inside method bodies, gated by
     'typeof window !== undefined' check (client returns 0, server
     actually queries)
… of client bundle

Root cause: utils/access.ts statically imported localAuth.ts (which imports
argon2, jsonwebtoken, prismaClient). access.ts is also imported from client
code (useQuotaStats, deepl.ts, etc.), so webpack/turbopack tried to bundle
argon2 -> node-gyp-build -> 'fs' module, which doesn't exist in browser.

Fix: replace 'import { verifyAccessToken } from ./localAuth' with
'const { verifyAccessToken } = await import(./localAuth)' inside
validateUserAndToken(). Same for prismaClient in getActualStorageUsage().

Dynamic import() is treated by webpack as a separate chunk that's only
loaded when actually called. Since validateUserAndToken is only called
from API routes (server-side), the localAuth/db chunk never loads in
browser.

This is the standard Next.js pattern for server-only utilities that need
to be type-shared with client code.
…n client bundle

Root cause: utils/supabase.ts statically imported verifyAccessToken from
./localAuth. AuthContext.tsx (client component) imports supabase from
utils/supabase.ts, so webpack bundled:
  supabase.ts -> localAuth.ts -> argon2 -> node-gyp-build -> 'fs' (FAIL)

Fix: change static import to dynamic import inside getUser() and
setSession() methods. The verifyAccessToken function only needs to run
when the user actually calls these methods (at runtime, on client),
so dynamic import() splits it into a separate chunk that's loaded on
demand.

This is the same pattern used in access.ts (commit 5e9515d).

The type import 'import type { AuthUser } from ./localAuth' is erased
at compile time and doesn't trigger any runtime module loading.
…uild

Even with dynamic import in access.ts and supabase.ts, Turbopack still
follows 'import type { AuthUser } from ./localAuth' as a static edge
and pulls argon2 -> node-gyp-build -> 'fs' into the client bundle.

The clean fix: alias these server-only modules to an empty stub
(src/utils/stub.ts) when NEXT_PUBLIC_APP_PLATFORM=web. This affects
ONLY the client bundle; server bundle (API routes) still gets the real
modules via Next.js's separate server compilation.

Aliases added to both webpack and turbopack config:
- argon2 -> false (webpack) / stub.ts (turbopack)
- @prisma/client -> false / stub.ts
- jsonwebtoken -> false / stub.ts

The stub.ts already exists (used for @tursodatabase/database-wasm in
non-web builds).
Each module has different import shapes (default vs named), so they
need separate stub files:
- stub-prisma.ts: named export PrismaClient
- stub-jwt.ts: default export + JwtPayload type
- stub-argon2.ts: default export (argon2 is CJS, imported as default)

Update next.config.mjs turbopack resolveAlias to point each module to
its specific stub file. Webpack aliases use 'false' (empty module) for
the same effect.
Next.js build with TS strict mode fails on 'declared but never read'.
Original Supabase version used these for composite cursor or-clause;
SQLite version simplified to orderBy + take, so the parsed cursor
values are no longer used. Replace with 'void rawCursor' to acknowledge
the param is read but its value is unused.
After removing the 'Upgrade to Readest Premium' menu item (commit dbdf6ac),
userProfilePlan is no longer used in SettingsMenu. TS strict mode flags
this as 'declared but never read'.
After removing all Stripe/IAP handlers (which were the only callers of
setLoading), the loading state was always false. Drop the state, the
Spinner overlay, and the unused Spinner import.
After removing the plan-gating logic, getAccessToken is no longer called
(plan was fetched with it before, but now we just call the API directly).
… to never

The stub PrismaClient had no fields, so when shareServer.ts (which gets
type-checked alongside client code) accessed row.revokedAt.toISOString(),
TS narrowed revokedAt to 'never' (because stub's PrismaClient has no
bookShare property).

Fix: declare PrismaClient and Prisma as 'any' in the stub. This makes
all field accesses valid from TS's perspective. The stub is only used
in client bundle; server bundle uses the real PrismaClient which has
proper types.

Also revert shareServer.ts to original 'row.revokedAt?.toISOString()' —
now valid because PrismaClient is any.
…stanceof

TS doesn't allow 'x instanceof Date' when x is 'any' (which is the case
now that stub PrismaClient is 'any'). Use 'new Date(x).toISOString()'
instead — works for both Date objects and ISO date strings (Prisma 5
returns Date, but the type is 'any' so we cover both).
Readest Lite Bot and others added 17 commits June 19, 2026 00:11
DBSyncTypeMap was a leftover from the original Supabase version (used to
map table names to response keys). Our Prisma version directly builds
the response object, so the constant is unused.
sinceIso was used by supabase .or() filter; Prisma version uses Date
object directly in 'updatedAt: { gt: since }' so the ISO string is
no longer needed.
…ET response

SyncRecord type expects snake_case field names (created_at, updated_at,
deleted_at) — these come from the original Supabase schema. The original
camelCase fields (createdAt, updatedAt, deletedAt) were kept for
backward compat with some client code, but SyncRecord type-checks
against snake_case.

Add both naming conventions to all three query functions (books,
configs, notes) and cast to SyncRecord[] via 'as unknown as'.
Prisma's SortOrder type is 'asc' | 'desc' (a string literal union), but
TypeScript widens string literals to 'string' when they appear in
plain object literals. This breaks type compatibility with Prisma's
findMany orderBy parameter.

Add 'as const' to all orderBy values across all API routes (sync.ts,
sync/replicas.ts, sync/replica-keys.ts, send/*.ts, share/list/route.ts,
storage/list.ts).

For storage/list.ts where sortOrder is dynamic, cast to 'asc' | 'desc'.
Hlc is a branded string type ('string & { __brand: "Hlc" }'). Prisma
returns plain string for our text columns, so direct assignment fails
type-check. Use 'as unknown as ReplicaRow[...]' to satisfy TS — the
runtime value is just a string, which is what Hlc is at runtime.
crdtMergeReplica's first parameter is ReplicaRow | null, which uses
snake_case field names (user_id, replica_id). The localRow object
constructed from Prisma's existing record was using camelCase, causing
type mismatch.

Also cast Hlc fields (deleted_at_ts, updated_at_ts) to branded type.
Two separate ReplicaRow interface definitions (one in utils/crdt.ts,
one in types/replica.ts) caused type incompatibility — TS treats them
as distinct types even though they have the same shape.

Fix: import and re-export ReplicaRow (and related Hlc/FieldEnvelope/
FieldsObject/Manifest) from types/replica.ts in utils/crdt.ts. All
call sites now reference the same type.
user/delete.ts doesn't actually use prismaClient — it just returns 403
to protect the only admin account. Remove the dead import.
…nterface

The stub class had arbitrary method names (exec, query) but the
DatabaseService interface requires execute, select, batch, close.
Match the interface exactly so TS strict mode passes.
Previous commit removed the 'const quota = getTranslationQuota(userPlan)'
line but left a reference to 'quota' in the quotaExceeded assignment.
Set quotaExceeded to false directly (Pro system is removed, quota is
unlimited).
Previous commit imported FieldEnvelope from types/replica.ts but left
the local interface definition, causing 'Import declaration conflicts
with local declaration' error.

FieldEnvelope from types/replica.ts is generic <V = unknown> with
t: Hlc (branded string), semantically equivalent to the local def.
ReplicaRow.manifest_jsonb is Manifest | null (with files: ManifestFile[]),
but ReplicaMergeInput.manifestJsonb was { files: unknown[]; schemaVersion }
which is incompatible. Use the imported Manifest type.
ReplicaRow expects deleted_at_ts: Hlc | null and updated_at_ts: Hlc
(branded string types). hlcMax returns plain string | null, so direct
assignment fails type-check. Cast via 'as unknown as Hlc'.
jsonwebtoken's expiresIn option computes the expiry timestamp itself,
so the manual 'now' was unused.
PHContext.tsx called atob(process.env['NEXT_PUBLIC_DEFAULT_POSTHOG_*_BASE64']!)
at module load time. In Docker build, these env vars are not set (only
runtime env), so atob(undefined as string) throws
'The string to be decoded is not correctly encoded' during
'Collecting page data' phase.

Wrap atob in safeAtob: returns empty string on undefined input or
decode failure. PostHog init guard (posthogKey truthy check) then
skips initialization gracefully.
…moke tests

Changes to match https://cshdotcom.github.io/readestl/deploy.html:

1. .env.example: simplified to only 3 required vars (ADMIN_EMAIL,
   ADMIN_PASSWORD, PORT). JWT_SECRET is now optional (auto-derived
   from ADMIN_EMAIL+ADMIN_PASSWORD when not set). Added PUBLIC_BASE_URL
   for reverse proxy scenario.

2. docker-compose.yml: switched to bind mount (./data:/data) for easier
   backup/migration. Uses ghcr.io image by default. Build option commented
   out for local development.

3. docker/entrypoint.sh: creates data/books/uploads and data/books/covers
   subdirs matching tutorial's directory structure. Writes a default
   /data/config.json if not present. Logs prisma output with tail -5
   for cleaner startup output.

4. utils/localAuth.ts: JWT_SECRET now has a fallback that derives from
   ADMIN_EMAIL + ADMIN_PASSWORD when JWT_SECRET env var is not set.
   This makes the container work out-of-the-box with just the 3 vars
   from the tutorial. Production users should still set JWT_SECRET
   explicitly.

5. .github/workflows/ci.yml: completely rewrote smoke test with:
   - 60s readiness polling (waits for prisma db push + init admin)
   - Container exit detection (catches crashes early)
   - 5 checks: settings, login, signup-disabled, sync-auth-required,
     sync-with-token-works
   - Detailed error output with docker logs on failure

6. README.md: aligned with tutorial's quick start (docker run one-liner,
   compose section, env table, data layout tree). Links to tutorial page.
…updates

Bumps the github-actions group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4` | `7` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3` | `4` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `6` | `7` |
| [docker/metadata-action](https://github.com/docker/metadata-action) | `5` | `6` |
| [docker/login-action](https://github.com/docker/login-action) | `3` | `4` |



Updates `actions/checkout` from 4 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v4...v7)

Updates `docker/setup-buildx-action` from 3 to 4
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@v3...v4)

Updates `docker/build-push-action` from 6 to 7
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@v6...v7)

Updates `docker/metadata-action` from 5 to 6
- [Release notes](https://github.com/docker/metadata-action/releases)
- [Commits](docker/metadata-action@v5...v6)

Updates `docker/login-action` from 3 to 4
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v3...v4)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/build-push-action
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/login-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/metadata-action
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/setup-buildx-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/github-actions-4ef91543cb branch from cb13b95 to 204c2b5 Compare June 19, 2026 02:32
@cshdotcom cshdotcom closed this Jun 20, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jun 20, 2026

Copy link
Copy Markdown
Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-4ef91543cb branch June 20, 2026 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant