From c766bf32a11cb41d4e6d3a015c778678f927132e Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Thu, 9 Jul 2026 20:42:00 -0700 Subject: [PATCH 01/57] Enable Dependabot auto-merge (#244) Enable squash auto-merge for same-repository Dependabot PRs after required checks pass and enforce the declared Node engine range during Docker builds. --- .github/workflows/dependabot-auto-merge.yml | 24 +++++++++++++++++++++ Dockerfile | 1 + 2 files changed, 25 insertions(+) create mode 100644 .github/workflows/dependabot-auto-merge.yml diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml new file mode 100644 index 0000000..3ed545c --- /dev/null +++ b/.github/workflows/dependabot-auto-merge.yml @@ -0,0 +1,24 @@ +name: Dependabot Auto Merge + +on: + pull_request_target: + types: [opened, synchronize, reopened, ready_for_review] + +permissions: + contents: write + pull-requests: write + +jobs: + enable-automerge: + if: > + github.event.pull_request.user.login == 'dependabot[bot]' && + startsWith(github.event.pull_request.head.ref, 'dependabot/') && + github.event.pull_request.head.repo.full_name == github.repository && + github.event.pull_request.draft == false + runs-on: ubuntu-latest + steps: + - name: Enable auto-merge + run: gh pr merge --auto --squash "$PR_URL" + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + PR_URL: ${{ github.event.pull_request.html_url }} diff --git a/Dockerfile b/Dockerfile index 1e29023..0bfbda4 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,7 @@ # syntax=docker/dockerfile:1.7 FROM node:24-alpine AS base +ENV NPM_CONFIG_ENGINE_STRICT=true RUN apk add --no-cache tini WORKDIR /app From 6aa362835fa2a62ee7a2e695225a8b673a2ab11a Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 9 Jul 2026 20:48:34 -0700 Subject: [PATCH 02/57] Bump azure/setup-helm from 4 to 5 (#241) Bumps [azure/setup-helm](https://github.com/azure/setup-helm) from 4 to 5. - [Release notes](https://github.com/azure/setup-helm/releases) - [Changelog](https://github.com/Azure/setup-helm/blob/main/CHANGELOG.md) - [Commits](https://github.com/azure/setup-helm/compare/v4...v5) --- updated-dependencies: - dependency-name: azure/setup-helm dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jon Fairbanks --- .github/workflows/ci.yaml | 2 +- .github/workflows/publish.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index ba7d44c..9290ec4 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -48,7 +48,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - - uses: azure/setup-helm@v4 + - uses: azure/setup-helm@v5 - run: helm lint chart - run: helm template docker-node-app chart --set autoscaling.enabled=true --set ingress.enabled=true diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 9cfa3a6..c16c3b0 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -64,7 +64,7 @@ jobs: - uses: actions/checkout@v6 with: ref: ${{ github.event.workflow_run.head_sha }} - - uses: azure/setup-helm@v4 + - uses: azure/setup-helm@v5 - name: Check out chart repository uses: actions/checkout@v6 with: From e15614c0ab5ddf30539ee97f3849455285c9abd7 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 10 Jul 2026 03:50:26 +0000 Subject: [PATCH 03/57] Bump actions/checkout from 6 to 7 (#242) Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Commits](https://github.com/actions/checkout/compare/v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/ci.yaml | 8 ++++---- .github/workflows/codeql.yml | 2 +- .github/workflows/publish.yaml | 6 +++--- .github/workflows/snyk.yml | 2 +- 4 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 9290ec4..b7f06c0 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -22,7 +22,7 @@ jobs: matrix: node-version: [22, 24] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: actions/setup-node@v6 with: node-version: ${{ matrix.node-version }} @@ -34,7 +34,7 @@ jobs: name: Lint and audit runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: actions/setup-node@v6 with: node-version: 24 @@ -47,7 +47,7 @@ jobs: name: Helm lint and render runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: azure/setup-helm@v5 - run: helm lint chart - run: helm template docker-node-app chart --set autoscaling.enabled=true --set ingress.enabled=true @@ -56,7 +56,7 @@ jobs: name: Build container runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: docker/setup-buildx-action@v4 - name: Build test target uses: docker/build-push-action@v7 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 0bdcea8..7ce83cb 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -17,7 +17,7 @@ jobs: name: Analyze JavaScript runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: github/codeql-action/init@v4 with: languages: javascript-typescript diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index c16c3b0..6430d1a 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -19,7 +19,7 @@ jobs: if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: ref: ${{ github.event.workflow_run.head_sha }} - name: Set up QEMU @@ -61,12 +61,12 @@ jobs: if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' && github.event.workflow_run.head_branch == 'master' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: ref: ${{ github.event.workflow_run.head_sha }} - uses: azure/setup-helm@v5 - name: Check out chart repository - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: repository: jonfairbanks/helm-charts token: ${{ secrets.HELM_CHARTS_PAT }} diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index afba1c5..fcd41ad 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -34,7 +34,7 @@ jobs: - name: Checkout if: env.SNYK_TOKEN != '' - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - name: Use Node.js 24.x if: env.SNYK_TOKEN != '' From abcb3b97667c93701df89f3cb7465c67412a6fcf Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Thu, 9 Jul 2026 21:19:11 -0700 Subject: [PATCH 04/57] Publish Helm chart to GHCR (#245) --- .github/workflows/publish.yaml | 55 ++++++++++++++++++---------------- 1 file changed, 30 insertions(+), 25 deletions(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 6430d1a..a67a66e 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -19,15 +19,15 @@ jobs: if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: ref: ${{ github.event.workflow_run.head_sha }} - name: Set up QEMU - uses: docker/setup-qemu-action@v4 + uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v4 + uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4 - name: Log in to Docker Hub - uses: docker/login-action@v4 + uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4 with: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_ACCESS_TOKEN }} @@ -36,7 +36,7 @@ jobs: run: echo "version=$(jq -r .version package.json)" >> "$GITHUB_OUTPUT" - name: Generate image metadata id: meta - uses: docker/metadata-action@v6 + uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6 with: images: jonfairbanks/docker-node-app tags: | @@ -45,7 +45,7 @@ jobs: type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'master' }} type=raw,value=${{ steps.package.outputs.version }},enable=${{ github.event.workflow_run.head_branch == 'master' }} - name: Build and push - uses: docker/build-push-action@v7 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7 with: context: . target: production @@ -60,27 +60,32 @@ jobs: name: Publish Helm chart if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' && github.event.workflow_run.head_branch == 'master' runs-on: ubuntu-latest + permissions: + contents: read + packages: write steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: ref: ${{ github.event.workflow_run.head_sha }} - - uses: azure/setup-helm@v5 - - name: Check out chart repository - uses: actions/checkout@v7 + fetch-depth: 2 + - name: Set up Helm + uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 with: - repository: jonfairbanks/helm-charts - token: ${{ secrets.HELM_CHARTS_PAT }} - path: helm-charts - - name: Package chart - run: helm package chart --destination helm-charts/_releases - - name: Publish chart package - working-directory: helm-charts - run: | - git config user.name "github-actions[bot]" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git add _releases - git diff --cached --quiet && exit 0 - git commit -m "Publish docker-node-app chart ${SOURCE_SHA::7}" - git push + version: v4.2.3 + - name: Publish chart to GHCR env: - SOURCE_SHA: ${{ github.event.workflow_run.head_sha }} + GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + version=$(awk '/^version:/ { print $2; exit }' chart/Chart.yaml) + chart=oci://ghcr.io/jonfairbanks/charts/docker-node-app + if helm show chart "$chart" --version "$version" >/dev/null 2>&1; then + if git diff --quiet HEAD^ HEAD -- chart; then + echo "${chart}:${version} already exists and this change does not modify the chart." + exit 0 + fi + echo "${chart}:${version} already exists; increment chart/Chart.yaml." >&2 + exit 1 + fi + echo "$GHCR_TOKEN" | helm registry login ghcr.io --username "$GITHUB_ACTOR" --password-stdin + helm package chart --destination /tmp/charts + helm push "/tmp/charts/docker-node-app-${version}.tgz" oci://ghcr.io/jonfairbanks/charts From 43d05f453d3a1b917826c25c70be066270200110 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Thu, 9 Jul 2026 21:31:12 -0700 Subject: [PATCH 05/57] Fix Helm chart non-root runtime (#246) --- chart/Chart.yaml | 2 +- chart/values.yaml | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/chart/Chart.yaml b/chart/Chart.yaml index d120fd9..6e06f81 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.0 +version: 3.0.1 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/chart/values.yaml b/chart/values.yaml index 9ada7e6..391d3e3 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -20,6 +20,8 @@ podLabels: {} podSecurityContext: runAsNonRoot: true + runAsUser: 1000 + runAsGroup: 1000 seccompProfile: type: RuntimeDefault From 9b26aa2d7482370a11174b92259311a886c31bf2 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Thu, 9 Jul 2026 22:05:12 -0700 Subject: [PATCH 06/57] Harden container runtime and CI validation (#247) --- .github/workflows/ci.yaml | 12 +++++-- .github/workflows/snyk.yml | 15 ++++++++- __tests__/shutdown.test.js | 59 ++++++++++++++++++++++++++++++++++ index.js | 66 +++++++++++++++++++++++++++++++++++--- 4 files changed, 145 insertions(+), 7 deletions(-) create mode 100644 __tests__/shutdown.test.js diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index b7f06c0..800e714 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -64,5 +64,13 @@ jobs: context: . target: test push: false - cache-from: type=gha - cache-to: type=gha,mode=max + cache-from: type=gha,scope=test + cache-to: type=gha,mode=max,scope=test + - name: Build production target + uses: docker/build-push-action@v7 + with: + context: . + target: production + push: false + cache-from: type=gha,scope=production + cache-to: type=gha,mode=max,scope=production diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index fcd41ad..41ba3fa 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -18,7 +18,7 @@ permissions: jobs: open-source: - name: Open Source + name: Open Source and Container if: >- github.actor != 'dependabot[bot]' && (github.event_name != 'pull_request' || @@ -55,3 +55,16 @@ jobs: --file=package.json --package-manager=npm --severity-threshold=high + + - name: Build production image + if: env.SNYK_TOKEN != '' + run: docker build --target production --tag docker-node-app:snyk . + + - name: Scan production image + if: env.SNYK_TOKEN != '' + uses: snyk/actions/docker@9adf32b1121593767fc3c057af55b55db032dc04 # v1.0.0 + with: + image: docker-node-app:snyk + args: >- + --file=Dockerfile + --severity-threshold=high diff --git a/__tests__/shutdown.test.js b/__tests__/shutdown.test.js new file mode 100644 index 0000000..24b6a9d --- /dev/null +++ b/__tests__/shutdown.test.js @@ -0,0 +1,59 @@ +const assert = require('node:assert/strict'); +const http = require('node:http'); +const { once } = require('node:events'); +const { test } = require('node:test'); +const { createGracefulShutdown } = require('../index'); + +test('graceful shutdown drains an in-flight request before closing', async (t) => { + let markRequestStarted; + let releaseResponse; + const requestStarted = new Promise((resolve) => { + markRequestStarted = resolve; + }); + const responseReleased = new Promise((resolve) => { + releaseResponse = resolve; + }); + + const server = http.createServer(async (_request, response) => { + markRequestStarted(); + await responseReleased; + response.end('ok'); + }); + server.keepAliveTimeout = 10; + + t.after(() => { + server.closeAllConnections?.(); + if (server.listening) { + server.close(); + } + }); + + server.listen(0, '127.0.0.1'); + await once(server, 'listening'); + const { port } = server.address(); + const responsePromise = fetch(`http://127.0.0.1:${port}`); + await requestStarted; + + const messages = []; + const logger = { + log: (message) => messages.push(message), + error: (message) => messages.push(message), + }; + const shutdown = createGracefulShutdown(server, { timeoutMs: 1000, logger }); + let shutdownComplete = false; + const shutdownPromise = shutdown('SIGTERM').then(() => { + shutdownComplete = true; + }); + + await new Promise((resolve) => setImmediate(resolve)); + assert.equal(shutdownComplete, false); + + releaseResponse(); + const response = await responsePromise; + assert.equal(await response.text(), 'ok'); + await shutdownPromise; + + assert.equal(shutdownComplete, true); + assert.equal(server.listening, false); + assert.deepEqual(messages, ['Received SIGTERM; draining active connections...']); +}); diff --git a/index.js b/index.js index 71f9d43..ea32424 100644 --- a/index.js +++ b/index.js @@ -1,8 +1,66 @@ // Setup Express const PORT = process.env.PORT || 8080; +const SHUTDOWN_TIMEOUT_MS = Number.parseInt( + process.env.SHUTDOWN_TIMEOUT_MS || '25000', + 10, +); const app = require('./app'); -// Launch the App -app.listen(PORT, '0.0.0.0', () => { - console.log(`docker-node-app is listening on port ${PORT}`); -}); +function startServer({ port = PORT, host = '0.0.0.0', logger = console } = {}) { + return app.listen(port, host, () => { + logger.log(`docker-node-app is listening on port ${port}`); + }); +} + +function createGracefulShutdown( + server, + { timeoutMs = SHUTDOWN_TIMEOUT_MS, logger = console } = {}, +) { + let shutdownPromise; + + return (signal) => { + if (shutdownPromise) { + return shutdownPromise; + } + + logger.log(`Received ${signal}; draining active connections...`); + shutdownPromise = new Promise((resolve, reject) => { + const timeout = setTimeout(() => { + logger.error(`Graceful shutdown exceeded ${timeoutMs}ms; forcing close.`); + server.closeAllConnections?.(); + reject(new Error('Graceful shutdown timed out')); + }, timeoutMs); + timeout.unref(); + + server.close((error) => { + clearTimeout(timeout); + if (error) { + reject(error); + return; + } + resolve(); + }); + server.closeIdleConnections?.(); + }); + + return shutdownPromise; + }; +} + +if (require.main === module) { + const server = startServer(); + const shutdown = createGracefulShutdown(server); + + for (const signal of ['SIGTERM', 'SIGINT']) { + process.once(signal, () => { + shutdown(signal) + .then(() => console.log('Graceful shutdown complete.')) + .catch((error) => { + console.error(error); + process.exitCode = 1; + }); + }); + } +} + +module.exports = { createGracefulShutdown, startServer }; From d8a22c87244caa9cef34efe09e9691d291a42476 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Thu, 9 Jul 2026 22:09:19 -0700 Subject: [PATCH 07/57] Scope container scan to OS dependencies (#249) --- .github/workflows/snyk.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index 41ba3fa..6e633cb 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -66,5 +66,6 @@ jobs: with: image: docker-node-app:snyk args: >- + --exclude-app-vulns --file=Dockerfile --severity-threshold=high From 017e0a87206b90372affefe792004f3fbdc398b8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 17 Jul 2026 05:43:30 +0000 Subject: [PATCH 08/57] Bump eslint from 10.6.0 to 10.7.0 in the npm group (#250) Bumps the npm group with 1 update: [eslint](https://github.com/eslint/eslint). Updates `eslint` from 10.6.0 to 10.7.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.7.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.7.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 14 +++++++------- package.json | 2 +- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/package-lock.json b/package-lock.json index 57d9e0b..c627772 100644 --- a/package-lock.json +++ b/package-lock.json @@ -15,7 +15,7 @@ }, "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.6.0", + "eslint": "^10.7.0", "globals": "^17.7.0", "supertest": "^7.2.2" }, @@ -681,9 +681,9 @@ "license": "MIT" }, "node_modules/eslint": { - "version": "10.6.0", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.6.0.tgz", - "integrity": "sha512-6lVbcqSodALYo+4ELD0heG6lFiFxnLMuLkiMi2qV8LMp54N8tE8FT1GMH+ev4Ti00nFjNze2+Su6DsV5OQW3Dg==", + "version": "10.7.0", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.7.0.tgz", + "integrity": "sha512-GVTD7s1vdIl6UYvAfriOPeY1Df8LIZjfofLvHwde+erDHGGuHyuM6xoxRxmHiebhYuD2p1vN4wWh0XzPARSGDQ==", "dev": true, "license": "MIT", "workspaces": [ @@ -2444,9 +2444,9 @@ "integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==" }, "eslint": { - "version": "10.6.0", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.6.0.tgz", - "integrity": "sha512-6lVbcqSodALYo+4ELD0heG6lFiFxnLMuLkiMi2qV8LMp54N8tE8FT1GMH+ev4Ti00nFjNze2+Su6DsV5OQW3Dg==", + "version": "10.7.0", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.7.0.tgz", + "integrity": "sha512-GVTD7s1vdIl6UYvAfriOPeY1Df8LIZjfofLvHwde+erDHGGuHyuM6xoxRxmHiebhYuD2p1vN4wWh0XzPARSGDQ==", "dev": true, "requires": { "@eslint-community/eslint-utils": "^4.8.0", diff --git a/package.json b/package.json index 5fd3bad..85dc330 100644 --- a/package.json +++ b/package.json @@ -25,7 +25,7 @@ "license": "MIT", "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.6.0", + "eslint": "^10.7.0", "globals": "^17.7.0", "supertest": "^7.2.2" } From a18b35aa80ad0297b9c879544ca004f57b90f880 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 17 Jul 2026 05:44:45 +0000 Subject: [PATCH 09/57] Bump actions/setup-node from 6 to 7 (#251) Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v6...v7) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/ci.yaml | 4 ++-- .github/workflows/snyk.yml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 800e714..a2f9d0d 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -23,7 +23,7 @@ jobs: node-version: [22, 24] steps: - uses: actions/checkout@v7 - - uses: actions/setup-node@v6 + - uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} cache: npm @@ -35,7 +35,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: actions/setup-node@v6 + - uses: actions/setup-node@v7 with: node-version: 24 cache: npm diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index 6e633cb..424b2df 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -38,7 +38,7 @@ jobs: - name: Use Node.js 24.x if: env.SNYK_TOKEN != '' - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 24.x cache: npm From 8b65f2827f54a49070b65d0d86398832f0c59bd3 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 24 Jul 2026 05:44:51 +0000 Subject: [PATCH 10/57] Bump actions/checkout from 7.0.0 to 7.0.1 (#252) Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1. - [Release notes](https://github.com/actions/checkout/releases) - [Commits](https://github.com/actions/checkout/compare/v7...v7.0.1) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/ci.yaml | 8 ++++---- .github/workflows/codeql.yml | 2 +- .github/workflows/publish.yaml | 4 ++-- .github/workflows/snyk.yml | 2 +- 4 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index a2f9d0d..b77e0bf 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -22,7 +22,7 @@ jobs: matrix: node-version: [22, 24] steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@v7.0.1 - uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} @@ -34,7 +34,7 @@ jobs: name: Lint and audit runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@v7.0.1 - uses: actions/setup-node@v7 with: node-version: 24 @@ -47,7 +47,7 @@ jobs: name: Helm lint and render runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@v7.0.1 - uses: azure/setup-helm@v5 - run: helm lint chart - run: helm template docker-node-app chart --set autoscaling.enabled=true --set ingress.enabled=true @@ -56,7 +56,7 @@ jobs: name: Build container runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@v7.0.1 - uses: docker/setup-buildx-action@v4 - name: Build test target uses: docker/build-push-action@v7 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7ce83cb..182539e 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -17,7 +17,7 @@ jobs: name: Analyze JavaScript runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@v7.0.1 - uses: github/codeql-action/init@v4 with: languages: javascript-typescript diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index a67a66e..3a9b816 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -19,7 +19,7 @@ jobs: if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' runs-on: ubuntu-latest steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ github.event.workflow_run.head_sha }} - name: Set up QEMU @@ -64,7 +64,7 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ github.event.workflow_run.head_sha }} fetch-depth: 2 diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index 424b2df..1373962 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -34,7 +34,7 @@ jobs: - name: Checkout if: env.SNYK_TOKEN != '' - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Use Node.js 24.x if: env.SNYK_TOKEN != '' From cacc6e5da792e3d8aa3346a7e50907211fbceec8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 24 Jul 2026 05:47:17 +0000 Subject: [PATCH 11/57] Bump docker/login-action from 4.4.0 to 4.5.0 (#253) Bumps [docker/login-action](https://github.com/docker/login-action) from 4.4.0 to 4.5.0. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/af1e73f918a031802d376d3c8bbc3fe56130a9b0...06fb636fac595d6fb4b28a5dfcb21a6f5091859c) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.5.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/publish.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 3a9b816..7f6cbf0 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -27,7 +27,7 @@ jobs: - name: Set up Docker Buildx uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4 - name: Log in to Docker Hub - uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4 + uses: docker/login-action@06fb636fac595d6fb4b28a5dfcb21a6f5091859c # v4 with: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_ACCESS_TOKEN }} From eb6c52ea23a0d882c94a843f97ac142ffb57b396 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Fri, 31 Jul 2026 23:09:20 -0700 Subject: [PATCH 12/57] Update brace-expansion lockfile (#258) --- package-lock.json | 114 ++++++++++++++++------------------------------ 1 file changed, 38 insertions(+), 76 deletions(-) diff --git a/package-lock.json b/package-lock.json index c627772..9106515 100644 --- a/package-lock.json +++ b/package-lock.json @@ -81,29 +81,6 @@ "node": "^20.19.0 || ^22.13.0 || >=24" } }, - "node_modules/@eslint/config-array/node_modules/balanced-match": { - "version": "4.0.4", - "resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-4.0.4.tgz", - "integrity": "sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==", - "dev": true, - "license": "MIT", - "engines": { - "node": "18 || 20 || >=22" - } - }, - "node_modules/@eslint/config-array/node_modules/brace-expansion": { - "version": "5.0.7", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.7.tgz", - "integrity": "sha512-7oFy703dxfY3/NLxC1fh2SUCQ0H9rmAY+5EpDVfXjUTTs+HEwR2nYaqLv+GWcTsumwxPfiz6CzCNkwXwBUwqCA==", - "dev": true, - "license": "MIT", - "dependencies": { - "balanced-match": "^4.0.2" - }, - "engines": { - "node": "18 || 20 || >=22" - } - }, "node_modules/@eslint/config-array/node_modules/minimatch": { "version": "10.2.5", "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-10.2.5.tgz", @@ -367,6 +344,16 @@ "dev": true, "license": "MIT" }, + "node_modules/balanced-match": { + "version": "4.0.4", + "resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-4.0.4.tgz", + "integrity": "sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==", + "dev": true, + "license": "MIT", + "engines": { + "node": "18 || 20 || >=22" + } + }, "node_modules/body-parser": { "version": "2.3.0", "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-2.3.0.tgz", @@ -404,6 +391,19 @@ "url": "https://opencollective.com/express" } }, + "node_modules/brace-expansion": { + "version": "5.0.9", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz", + "integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==", + "dev": true, + "license": "MIT", + "dependencies": { + "balanced-match": "^4.0.2" + }, + "engines": { + "node": "20 || >=22" + } + }, "node_modules/bytes": { "version": "3.1.2", "resolved": "https://registry.npmjs.org/bytes/-/bytes-3.1.2.tgz", @@ -771,29 +771,6 @@ "url": "https://opencollective.com/eslint" } }, - "node_modules/eslint/node_modules/balanced-match": { - "version": "4.0.4", - "resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-4.0.4.tgz", - "integrity": "sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==", - "dev": true, - "license": "MIT", - "engines": { - "node": "18 || 20 || >=22" - } - }, - "node_modules/eslint/node_modules/brace-expansion": { - "version": "5.0.7", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.7.tgz", - "integrity": "sha512-7oFy703dxfY3/NLxC1fh2SUCQ0H9rmAY+5EpDVfXjUTTs+HEwR2nYaqLv+GWcTsumwxPfiz6CzCNkwXwBUwqCA==", - "dev": true, - "license": "MIT", - "dependencies": { - "balanced-match": "^4.0.2" - }, - "engines": { - "node": "18 || 20 || >=22" - } - }, "node_modules/eslint/node_modules/escape-string-regexp": { "version": "4.0.0", "resolved": "https://registry.npmjs.org/escape-string-regexp/-/escape-string-regexp-4.0.0.tgz", @@ -2061,21 +2038,6 @@ "minimatch": "^10.2.4" }, "dependencies": { - "balanced-match": { - "version": "4.0.4", - "resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-4.0.4.tgz", - "integrity": "sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==", - "dev": true - }, - "brace-expansion": { - "version": "5.0.7", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.7.tgz", - "integrity": "sha512-7oFy703dxfY3/NLxC1fh2SUCQ0H9rmAY+5EpDVfXjUTTs+HEwR2nYaqLv+GWcTsumwxPfiz6CzCNkwXwBUwqCA==", - "dev": true, - "requires": { - "balanced-match": "^4.0.2" - } - }, "minimatch": { "version": "10.2.5", "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-10.2.5.tgz", @@ -2245,6 +2207,12 @@ "integrity": "sha512-Oei9OH4tRh0YqU3GxhX79dM/mwVgvbZJaSNaRk+bshkj0S5cfHcgYakreBjrHwatXKbz+IoIdYLxrKim2MjW0Q==", "dev": true }, + "balanced-match": { + "version": "4.0.4", + "resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-4.0.4.tgz", + "integrity": "sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==", + "dev": true + }, "body-parser": { "version": "2.3.0", "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-2.3.0.tgz", @@ -2268,6 +2236,15 @@ } } }, + "brace-expansion": { + "version": "5.0.9", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz", + "integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==", + "dev": true, + "requires": { + "balanced-match": "^4.0.2" + } + }, "bytes": { "version": "3.1.2", "resolved": "https://registry.npmjs.org/bytes/-/bytes-3.1.2.tgz", @@ -2481,21 +2458,6 @@ "optionator": "^0.9.3" }, "dependencies": { - "balanced-match": { - "version": "4.0.4", - "resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-4.0.4.tgz", - "integrity": "sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==", - "dev": true - }, - "brace-expansion": { - "version": "5.0.7", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.7.tgz", - "integrity": "sha512-7oFy703dxfY3/NLxC1fh2SUCQ0H9rmAY+5EpDVfXjUTTs+HEwR2nYaqLv+GWcTsumwxPfiz6CzCNkwXwBUwqCA==", - "dev": true, - "requires": { - "balanced-match": "^4.0.2" - } - }, "escape-string-regexp": { "version": "4.0.0", "resolved": "https://registry.npmjs.org/escape-string-regexp/-/escape-string-regexp-4.0.0.tgz", From ca5ed82437b2960cc79d0aa6d061b95f057872f4 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 1 Aug 2026 06:11:47 +0000 Subject: [PATCH 13/57] Bump docker/login-action from 4.5.0 to 4.6.0 (#256) Bumps [docker/login-action](https://github.com/docker/login-action) from 4.5.0 to 4.6.0. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/06fb636fac595d6fb4b28a5dfcb21a6f5091859c...dbcb813823bdd20940b903addbd779551569679f) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.5.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/publish.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 7f6cbf0..9ac7fd8 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -27,7 +27,7 @@ jobs: - name: Set up Docker Buildx uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4 - name: Log in to Docker Hub - uses: docker/login-action@06fb636fac595d6fb4b28a5dfcb21a6f5091859c # v4 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 with: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_ACCESS_TOKEN }} From fe492b13bb3b77a32e263192a77fb367a9dbb6da Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 1 Aug 2026 06:14:07 +0000 Subject: [PATCH 14/57] Bump the npm group across 1 directory with 2 updates (#254) Bumps the npm group with 2 updates in the / directory: [eslint](https://github.com/eslint/eslint) and [globals](https://github.com/sindresorhus/globals). Updates `eslint` from 10.7.0 to 10.8.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v10.7.0...v10.8.0) Updates `globals` from 17.7.0 to 17.8.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](https://github.com/sindresorhus/globals/compare/v17.7.0...v17.8.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.8.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: globals dependency-version: 17.8.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 48 +++++++++++++++++++++++------------------------ package.json | 4 ++-- 2 files changed, 26 insertions(+), 26 deletions(-) diff --git a/package-lock.json b/package-lock.json index 9106515..eb02f51 100644 --- a/package-lock.json +++ b/package-lock.json @@ -15,8 +15,8 @@ }, "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.7.0", - "globals": "^17.7.0", + "eslint": "^10.8.0", + "globals": "^17.8.0", "supertest": "^7.2.2" }, "engines": { @@ -98,9 +98,9 @@ } }, "node_modules/@eslint/config-helpers": { - "version": "0.6.0", - "resolved": "https://registry.npmjs.org/@eslint/config-helpers/-/config-helpers-0.6.0.tgz", - "integrity": "sha512-ii6Bw9jJ2zi2cWA2Z+9/QZ/+3DX6kwaV5Q986D/CdP3Lap3w/pgQZ373FV7byY/i7L4IRH/G43I5dz1ClsCbpA==", + "version": "0.7.0", + "resolved": "https://registry.npmjs.org/@eslint/config-helpers/-/config-helpers-0.7.0.tgz", + "integrity": "sha512-DObd/KKUsU+FaFv4PLxSRenpXfQWmPXXP3pPZ6/K1PCrMu2vQpMDMuQe/BqYeoLcz8ro0bVDF1RxOJgfVEdhUw==", "dev": true, "license": "Apache-2.0", "dependencies": { @@ -681,9 +681,9 @@ "license": "MIT" }, "node_modules/eslint": { - "version": "10.7.0", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.7.0.tgz", - "integrity": "sha512-GVTD7s1vdIl6UYvAfriOPeY1Df8LIZjfofLvHwde+erDHGGuHyuM6xoxRxmHiebhYuD2p1vN4wWh0XzPARSGDQ==", + "version": "10.8.0", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.0.tgz", + "integrity": "sha512-nuKKvN+oIBO0koN7Tm7dlkmnkc21mtt0QJLwAKzjLq14y6lRTdVG36MZHJ8eQHwdJMwZbQNMlPOYedMq/oVJvQ==", "dev": true, "license": "MIT", "workspaces": [ @@ -693,7 +693,7 @@ "@eslint-community/eslint-utils": "^4.8.0", "@eslint-community/regexpp": "^4.12.2", "@eslint/config-array": "^0.23.5", - "@eslint/config-helpers": "^0.6.0", + "@eslint/config-helpers": "^0.7.0", "@eslint/core": "^1.2.1", "@eslint/plugin-kit": "^0.7.2", "@humanfs/node": "^0.16.6", @@ -717,7 +717,7 @@ "imurmurhash": "^0.1.4", "is-glob": "^4.0.0", "json-stable-stringify-without-jsonify": "^1.0.1", - "minimatch": "^10.2.4", + "minimatch": "^10.2.5", "natural-compare": "^1.4.0", "optionator": "^0.9.3" }, @@ -1147,9 +1147,9 @@ } }, "node_modules/globals": { - "version": "17.7.0", - "resolved": "https://registry.npmjs.org/globals/-/globals-17.7.0.tgz", - "integrity": "sha512-Czmyns5dUsq4seFBR/Kdydhmo8y9kC79hiSkPn0YcGtNnYWnrgt0vjrSjx9tspoDGWm2CMarffRuLjM4xUz8xg==", + "version": "17.8.0", + "resolved": "https://registry.npmjs.org/globals/-/globals-17.8.0.tgz", + "integrity": "sha512-Zz/LMDZScFmkakeL2cTHzf+PbWKdpU3uclqkZT7TjDG58j5WPt0PpA+n9uPI24fZtlw07q0OtEi84K+umsRzqQ==", "dev": true, "license": "MIT", "engines": { @@ -2050,9 +2050,9 @@ } }, "@eslint/config-helpers": { - "version": "0.6.0", - "resolved": "https://registry.npmjs.org/@eslint/config-helpers/-/config-helpers-0.6.0.tgz", - "integrity": "sha512-ii6Bw9jJ2zi2cWA2Z+9/QZ/+3DX6kwaV5Q986D/CdP3Lap3w/pgQZ373FV7byY/i7L4IRH/G43I5dz1ClsCbpA==", + "version": "0.7.0", + "resolved": "https://registry.npmjs.org/@eslint/config-helpers/-/config-helpers-0.7.0.tgz", + "integrity": "sha512-DObd/KKUsU+FaFv4PLxSRenpXfQWmPXXP3pPZ6/K1PCrMu2vQpMDMuQe/BqYeoLcz8ro0bVDF1RxOJgfVEdhUw==", "dev": true, "requires": { "@eslint/core": "^1.2.1" @@ -2421,15 +2421,15 @@ "integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==" }, "eslint": { - "version": "10.7.0", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.7.0.tgz", - "integrity": "sha512-GVTD7s1vdIl6UYvAfriOPeY1Df8LIZjfofLvHwde+erDHGGuHyuM6xoxRxmHiebhYuD2p1vN4wWh0XzPARSGDQ==", + "version": "10.8.0", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.0.tgz", + "integrity": "sha512-nuKKvN+oIBO0koN7Tm7dlkmnkc21mtt0QJLwAKzjLq14y6lRTdVG36MZHJ8eQHwdJMwZbQNMlPOYedMq/oVJvQ==", "dev": true, "requires": { "@eslint-community/eslint-utils": "^4.8.0", "@eslint-community/regexpp": "^4.12.2", "@eslint/config-array": "^0.23.5", - "@eslint/config-helpers": "^0.6.0", + "@eslint/config-helpers": "^0.7.0", "@eslint/core": "^1.2.1", "@eslint/plugin-kit": "^0.7.2", "@humanfs/node": "^0.16.6", @@ -2453,7 +2453,7 @@ "imurmurhash": "^0.1.4", "is-glob": "^4.0.0", "json-stable-stringify-without-jsonify": "^1.0.1", - "minimatch": "^10.2.4", + "minimatch": "^10.2.5", "natural-compare": "^1.4.0", "optionator": "^0.9.3" }, @@ -2738,9 +2738,9 @@ } }, "globals": { - "version": "17.7.0", - "resolved": "https://registry.npmjs.org/globals/-/globals-17.7.0.tgz", - "integrity": "sha512-Czmyns5dUsq4seFBR/Kdydhmo8y9kC79hiSkPn0YcGtNnYWnrgt0vjrSjx9tspoDGWm2CMarffRuLjM4xUz8xg==", + "version": "17.8.0", + "resolved": "https://registry.npmjs.org/globals/-/globals-17.8.0.tgz", + "integrity": "sha512-Zz/LMDZScFmkakeL2cTHzf+PbWKdpU3uclqkZT7TjDG58j5WPt0PpA+n9uPI24fZtlw07q0OtEi84K+umsRzqQ==", "dev": true }, "gopd": { diff --git a/package.json b/package.json index 85dc330..e61c8b7 100644 --- a/package.json +++ b/package.json @@ -25,8 +25,8 @@ "license": "MIT", "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.7.0", - "globals": "^17.7.0", + "eslint": "^10.8.0", + "globals": "^17.8.0", "supertest": "^7.2.2" } } From bd035ba6eaa51579a7793157adbfea6c460e3b1a Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 1 Aug 2026 06:15:43 +0000 Subject: [PATCH 15/57] Bump github/codeql-action from 4 to 4.37.3 (#257) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.37.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/v4...v4.37.3) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jon Fairbanks --- .github/workflows/codeql.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 182539e..38f4d10 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7.0.1 - - uses: github/codeql-action/init@v4 + - uses: github/codeql-action/init@v4.37.3 with: languages: javascript-typescript - - uses: github/codeql-action/analyze@v4 + - uses: github/codeql-action/analyze@v4.37.3 From 821a063f41bc84ee2ff17cfcd41add11d4b0b9d6 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Fri, 31 Jul 2026 23:23:56 -0700 Subject: [PATCH 16/57] Upgrade runtime to Node 26 (#259) * Upgrade runtime to Node 26 * Sync Node 26 engine lockfile --- .github/workflows/ci.yaml | 4 ++-- Dockerfile | 2 +- README.md | 4 ++-- package-lock.json | 2 +- package.json | 4 ++-- 5 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index b77e0bf..3bbda41 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -20,7 +20,7 @@ jobs: strategy: fail-fast: false matrix: - node-version: [22, 24] + node-version: [26] steps: - uses: actions/checkout@v7.0.1 - uses: actions/setup-node@v7 @@ -37,7 +37,7 @@ jobs: - uses: actions/checkout@v7.0.1 - uses: actions/setup-node@v7 with: - node-version: 24 + node-version: 26 cache: npm - run: npm ci - run: npm run lint diff --git a/Dockerfile b/Dockerfile index 0bfbda4..7253671 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ # syntax=docker/dockerfile:1.7 -FROM node:24-alpine AS base +FROM node:26-alpine AS base ENV NPM_CONFIG_ENGINE_STRICT=true RUN apk add --no-cache tini WORKDIR /app diff --git a/README.md b/README.md index e6ddaf4..a1599e9 100644 --- a/README.md +++ b/README.md @@ -11,7 +11,7 @@ ## A sample Node.js app in Docker -- Uses Node.js 24 LTS +- Uses Node.js 26 - Reproducible npm installs from the committed lockfile - Runs as a non-root user for enhanced security - Multi-stage development, test, and production images @@ -20,7 +20,7 @@ ### Local development -With Node.js 24 installed: +With Node.js 26 installed: ```shell npm ci diff --git a/package-lock.json b/package-lock.json index eb02f51..0351629 100644 --- a/package-lock.json +++ b/package-lock.json @@ -20,7 +20,7 @@ "supertest": "^7.2.2" }, "engines": { - "node": ">=22.13 <25", + "node": ">=26 <27", "npm": ">=10" } }, diff --git a/package.json b/package.json index e61c8b7..c8ecf38 100644 --- a/package.json +++ b/package.json @@ -13,10 +13,10 @@ "test:watch": "node --test --watch" }, "engines": { - "node": ">=22.13 <25", + "node": ">=26 <27", "npm": ">=10" }, - "packageManager": "npm@11.11.0", + "packageManager": "npm@11.17.0", "dependencies": { "dayjs": "^1.11.21", "ejs": "^6.0.1", From 6286b9cb3a0d8031a3d1dd509f5b23827e66568e Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 7 Aug 2026 05:43:48 +0000 Subject: [PATCH 17/57] Bump globals from 17.8.0 to 17.9.0 in the npm group (#260) Bumps the npm group with 1 update: [globals](https://github.com/sindresorhus/globals). Updates `globals` from 17.8.0 to 17.9.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](https://github.com/sindresorhus/globals/compare/v17.8.0...v17.9.0) --- updated-dependencies: - dependency-name: globals dependency-version: 17.9.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 14 +++++++------- package.json | 2 +- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/package-lock.json b/package-lock.json index 0351629..20b0eec 100644 --- a/package-lock.json +++ b/package-lock.json @@ -16,7 +16,7 @@ "devDependencies": { "@eslint/js": "^10.0.1", "eslint": "^10.8.0", - "globals": "^17.8.0", + "globals": "^17.9.0", "supertest": "^7.2.2" }, "engines": { @@ -1147,9 +1147,9 @@ } }, "node_modules/globals": { - "version": "17.8.0", - "resolved": "https://registry.npmjs.org/globals/-/globals-17.8.0.tgz", - "integrity": "sha512-Zz/LMDZScFmkakeL2cTHzf+PbWKdpU3uclqkZT7TjDG58j5WPt0PpA+n9uPI24fZtlw07q0OtEi84K+umsRzqQ==", + "version": "17.9.0", + "resolved": "https://registry.npmjs.org/globals/-/globals-17.9.0.tgz", + "integrity": "sha512-m/MvAW61QVU5VDNF1Vj8axt016h8w7L5TU1e9zlab7XIttAT2YAlCwl75K1fOqvMM9apmD7lbCIRhpfkhmxhCg==", "dev": true, "license": "MIT", "engines": { @@ -2738,9 +2738,9 @@ } }, "globals": { - "version": "17.8.0", - "resolved": "https://registry.npmjs.org/globals/-/globals-17.8.0.tgz", - "integrity": "sha512-Zz/LMDZScFmkakeL2cTHzf+PbWKdpU3uclqkZT7TjDG58j5WPt0PpA+n9uPI24fZtlw07q0OtEi84K+umsRzqQ==", + "version": "17.9.0", + "resolved": "https://registry.npmjs.org/globals/-/globals-17.9.0.tgz", + "integrity": "sha512-m/MvAW61QVU5VDNF1Vj8axt016h8w7L5TU1e9zlab7XIttAT2YAlCwl75K1fOqvMM9apmD7lbCIRhpfkhmxhCg==", "dev": true }, "gopd": { diff --git a/package.json b/package.json index c8ecf38..f075a96 100644 --- a/package.json +++ b/package.json @@ -26,7 +26,7 @@ "devDependencies": { "@eslint/js": "^10.0.1", "eslint": "^10.8.0", - "globals": "^17.8.0", + "globals": "^17.9.0", "supertest": "^7.2.2" } } From ff9aeb9c74ac8282a482bbf45bda43e0421b9f83 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 7 Aug 2026 05:46:50 +0000 Subject: [PATCH 18/57] Bump github/codeql-action from 4.37.3 to 4.37.6 (#261) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.3 to 4.37.6. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/v4.37.3...v4.37.6) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 38f4d10..07f40e8 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7.0.1 - - uses: github/codeql-action/init@v4.37.3 + - uses: github/codeql-action/init@v4.37.6 with: languages: javascript-typescript - - uses: github/codeql-action/analyze@v4.37.3 + - uses: github/codeql-action/analyze@v4.37.6 From b9033e91ba7562e01d86854c28d54a20632d90b1 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Sat, 8 Aug 2026 22:45:27 -0700 Subject: [PATCH 19/57] Fix ingress URL in Helm notes (#262) --- chart/templates/NOTES.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/chart/templates/NOTES.txt b/chart/templates/NOTES.txt index ae44513..0f242c5 100644 --- a/chart/templates/NOTES.txt +++ b/chart/templates/NOTES.txt @@ -2,7 +2,7 @@ {{- if .Values.ingress.enabled }} {{- range $host := .Values.ingress.hosts }} {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ . }} + http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} {{- end }} {{- end }} {{- else if contains "NodePort" .Values.service.type }} From d938f32bc1f04c00a780d539b03a606aa2b42fc4 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Sat, 8 Aug 2026 22:53:07 -0700 Subject: [PATCH 20/57] Configure timezone for Helm workloads (#263) --- Dockerfile | 2 +- README.md | 7 +++++++ chart/Chart.yaml | 2 +- chart/templates/deployment.yaml | 2 ++ chart/values.yaml | 1 + 5 files changed, 12 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 7253671..e9937dc 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,7 @@ FROM node:26-alpine AS base ENV NPM_CONFIG_ENGINE_STRICT=true -RUN apk add --no-cache tini +RUN apk add --no-cache tini tzdata WORKDIR /app FROM base AS dependencies diff --git a/README.md b/README.md index a1599e9..fae554b 100644 --- a/README.md +++ b/README.md @@ -68,6 +68,13 @@ helm lint chart helm upgrade --install docker-node-app chart ``` +The chart sets the pod timezone to `America/Los_Angeles`. Override it with an +IANA timezone name when deploying elsewhere: + +```shell +helm upgrade --install docker-node-app chart --set timezone=Europe/London +``` + For testing that pods are balancing correctly, you can make multiple requests to your app to verify. To make 50 requests and write them to a file, you can run the following with your endpoint: diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 6e06f81..5eaf83d 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.1 +version: 3.0.2 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/chart/templates/deployment.yaml b/chart/templates/deployment.yaml index 861322c..5770ed5 100644 --- a/chart/templates/deployment.yaml +++ b/chart/templates/deployment.yaml @@ -44,6 +44,8 @@ spec: env: - name: NODE_ENV value: production + - name: TZ + value: {{ .Values.timezone | quote }} livenessProbe: {{- toYaml .Values.livenessProbe | nindent 12 }} readinessProbe: diff --git a/chart/values.yaml b/chart/values.yaml index 391d3e3..88ebbd4 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -8,6 +8,7 @@ image: imagePullSecrets: [] nameOverride: "" fullnameOverride: "" +timezone: America/Los_Angeles serviceAccount: create: true From 0653d1c9267866db5aeb9643ff7b4884d1ab2109 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 14 Aug 2026 05:43:51 +0000 Subject: [PATCH 21/57] Bump eslint from 10.8.0 to 10.8.1 in the npm group (#264) Bumps the npm group with 1 update: [eslint](https://github.com/eslint/eslint). Updates `eslint` from 10.8.0 to 10.8.1 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v10.8.0...v10.8.1) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.8.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 14 +++++++------- package.json | 2 +- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/package-lock.json b/package-lock.json index 20b0eec..7df96ba 100644 --- a/package-lock.json +++ b/package-lock.json @@ -15,7 +15,7 @@ }, "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.8.0", + "eslint": "^10.8.1", "globals": "^17.9.0", "supertest": "^7.2.2" }, @@ -681,9 +681,9 @@ "license": "MIT" }, "node_modules/eslint": { - "version": "10.8.0", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.0.tgz", - "integrity": "sha512-nuKKvN+oIBO0koN7Tm7dlkmnkc21mtt0QJLwAKzjLq14y6lRTdVG36MZHJ8eQHwdJMwZbQNMlPOYedMq/oVJvQ==", + "version": "10.8.1", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.1.tgz", + "integrity": "sha512-wqA7W2jbsC/BnV9Iv1UZpKVFkO1AdNoSmYW8NWG4HNOBbkAMvIqDZ27pI2f07dqn583NcIC44ckjAcOXDL1QbQ==", "dev": true, "license": "MIT", "workspaces": [ @@ -2421,9 +2421,9 @@ "integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==" }, "eslint": { - "version": "10.8.0", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.0.tgz", - "integrity": "sha512-nuKKvN+oIBO0koN7Tm7dlkmnkc21mtt0QJLwAKzjLq14y6lRTdVG36MZHJ8eQHwdJMwZbQNMlPOYedMq/oVJvQ==", + "version": "10.8.1", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.1.tgz", + "integrity": "sha512-wqA7W2jbsC/BnV9Iv1UZpKVFkO1AdNoSmYW8NWG4HNOBbkAMvIqDZ27pI2f07dqn583NcIC44ckjAcOXDL1QbQ==", "dev": true, "requires": { "@eslint-community/eslint-utils": "^4.8.0", diff --git a/package.json b/package.json index f075a96..ec960b8 100644 --- a/package.json +++ b/package.json @@ -25,7 +25,7 @@ "license": "MIT", "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.8.0", + "eslint": "^10.8.1", "globals": "^17.9.0", "supertest": "^7.2.2" } From 821f274936c5764b66d5db4cc4ebc401d05acd14 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Thu, 20 Aug 2026 01:28:33 -0700 Subject: [PATCH 22/57] Lower HPA minimum replicas (#266) --- chart/Chart.yaml | 2 +- chart/values.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 5eaf83d..69e3da5 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.2 +version: 3.0.3 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/chart/values.yaml b/chart/values.yaml index 88ebbd4..51d5a65 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -73,7 +73,7 @@ readinessProbe: autoscaling: enabled: false - minReplicas: 3 + minReplicas: 2 maxReplicas: 10 targetCPUUtilizationPercentage: 70 targetMemoryUtilizationPercentage: "" From 444c7908c0257ee14269942b1997716d3d7c6ea7 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Thu, 20 Aug 2026 02:15:17 -0700 Subject: [PATCH 23/57] Update Helm chart resource defaults (#267) * Lower HPA minimum replicas * Update Helm chart resource defaults * Remove Helm resource test script --- chart/Chart.yaml | 2 +- chart/values.yaml | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 69e3da5..63872ce 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.3 +version: 3.0.4 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/chart/values.yaml b/chart/values.yaml index 51d5a65..b43d936 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -53,9 +53,9 @@ ingress: resources: requests: cpu: 10m - memory: 90Mi - limits: memory: 128Mi + limits: + memory: 192Mi livenessProbe: httpGet: From 0d6c86ba8630eb8e811764f39db108a2984a0c23 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 21 Aug 2026 05:43:49 +0000 Subject: [PATCH 24/57] Bump the npm group with 2 updates (#268) Bumps the npm group with 2 updates: [dayjs](https://github.com/iamkun/dayjs) and [globals](https://github.com/sindresorhus/globals). Updates `dayjs` from 1.11.21 to 1.11.23 - [Release notes](https://github.com/iamkun/dayjs/releases) - [Changelog](https://github.com/iamkun/dayjs/blob/v1.11.23/CHANGELOG.md) - [Commits](https://github.com/iamkun/dayjs/compare/v1.11.21...v1.11.23) Updates `globals` from 17.9.0 to 17.11.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](https://github.com/sindresorhus/globals/compare/v17.9.0...v17.11.0) --- updated-dependencies: - dependency-name: dayjs dependency-version: 1.11.23 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm - dependency-name: globals dependency-version: 17.11.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 28 ++++++++++++++-------------- package.json | 4 ++-- 2 files changed, 16 insertions(+), 16 deletions(-) diff --git a/package-lock.json b/package-lock.json index 7df96ba..1508c81 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9,14 +9,14 @@ "version": "3.0.0", "license": "MIT", "dependencies": { - "dayjs": "^1.11.21", + "dayjs": "^1.11.23", "ejs": "^6.0.1", "express": "^5.2.1" }, "devDependencies": { "@eslint/js": "^10.0.1", "eslint": "^10.8.1", - "globals": "^17.9.0", + "globals": "^17.11.0", "supertest": "^7.2.2" }, "engines": { @@ -528,9 +528,9 @@ } }, "node_modules/dayjs": { - "version": "1.11.21", - "resolved": "https://registry.npmjs.org/dayjs/-/dayjs-1.11.21.tgz", - "integrity": "sha512-98IT+HOahAisibz/yjKbzuOBwYcjJ7BCLPzARyHiyEBmRz4fatF+KPJszEHXsGYjUG234aH/cOjW1wwTbKUZlA==", + "version": "1.11.23", + "resolved": "https://registry.npmjs.org/dayjs/-/dayjs-1.11.23.tgz", + "integrity": "sha512-QDTCU0M0MxR3hQfnlDJfwekQiaanm1ubOD231u73WBckQ/fsamwRLiE2GBz6D3a/xF1NgfiDLJjXBa1hYOYTtQ==", "license": "MIT" }, "node_modules/debug": { @@ -1147,9 +1147,9 @@ } }, "node_modules/globals": { - "version": "17.9.0", - "resolved": "https://registry.npmjs.org/globals/-/globals-17.9.0.tgz", - "integrity": "sha512-m/MvAW61QVU5VDNF1Vj8axt016h8w7L5TU1e9zlab7XIttAT2YAlCwl75K1fOqvMM9apmD7lbCIRhpfkhmxhCg==", + "version": "17.11.0", + "resolved": "https://registry.npmjs.org/globals/-/globals-17.11.0.tgz", + "integrity": "sha512-Z2I8hM+PbJDXQDq3Icgpzv+mPdwr68iZUU9d5WW4FuXfDUQfkZaZuvjMv42/5crNyw154+9+VWXbYrUgDXbxNw==", "dev": true, "license": "MIT", "engines": { @@ -2321,9 +2321,9 @@ } }, "dayjs": { - "version": "1.11.21", - "resolved": "https://registry.npmjs.org/dayjs/-/dayjs-1.11.21.tgz", - "integrity": "sha512-98IT+HOahAisibz/yjKbzuOBwYcjJ7BCLPzARyHiyEBmRz4fatF+KPJszEHXsGYjUG234aH/cOjW1wwTbKUZlA==" + "version": "1.11.23", + "resolved": "https://registry.npmjs.org/dayjs/-/dayjs-1.11.23.tgz", + "integrity": "sha512-QDTCU0M0MxR3hQfnlDJfwekQiaanm1ubOD231u73WBckQ/fsamwRLiE2GBz6D3a/xF1NgfiDLJjXBa1hYOYTtQ==" }, "debug": { "version": "4.4.3", @@ -2738,9 +2738,9 @@ } }, "globals": { - "version": "17.9.0", - "resolved": "https://registry.npmjs.org/globals/-/globals-17.9.0.tgz", - "integrity": "sha512-m/MvAW61QVU5VDNF1Vj8axt016h8w7L5TU1e9zlab7XIttAT2YAlCwl75K1fOqvMM9apmD7lbCIRhpfkhmxhCg==", + "version": "17.11.0", + "resolved": "https://registry.npmjs.org/globals/-/globals-17.11.0.tgz", + "integrity": "sha512-Z2I8hM+PbJDXQDq3Icgpzv+mPdwr68iZUU9d5WW4FuXfDUQfkZaZuvjMv42/5crNyw154+9+VWXbYrUgDXbxNw==", "dev": true }, "gopd": { diff --git a/package.json b/package.json index ec960b8..c3318b7 100644 --- a/package.json +++ b/package.json @@ -18,7 +18,7 @@ }, "packageManager": "npm@11.17.0", "dependencies": { - "dayjs": "^1.11.21", + "dayjs": "^1.11.23", "ejs": "^6.0.1", "express": "^5.2.1" }, @@ -26,7 +26,7 @@ "devDependencies": { "@eslint/js": "^10.0.1", "eslint": "^10.8.1", - "globals": "^17.9.0", + "globals": "^17.11.0", "supertest": "^7.2.2" } } From fe9f8020d7aac3f68c15dac58b1f28a34b5b5bf2 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Fri, 21 Aug 2026 01:12:20 -0700 Subject: [PATCH 25/57] Bump Helm chart to 3.0.5 (#270) --- chart/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 63872ce..3f8e473 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.4 +version: 3.0.5 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to From eaa4b6d74d015bbc1d09ad2e9191926abb5f4ab0 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Mon, 24 Aug 2026 21:58:07 -0700 Subject: [PATCH 26/57] Restrict Dependabot auto-merge to non-major updates (#271) --- .github/workflows/dependabot-auto-merge.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index 3ed545c..cc21112 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -17,7 +17,16 @@ jobs: github.event.pull_request.draft == false runs-on: ubuntu-latest steps: + - name: Fetch Dependabot metadata + id: metadata + uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + with: + github-token: ${{ secrets.GITHUB_TOKEN }} + - name: Enable auto-merge + if: > + steps.metadata.outputs.update-type == 'version-update:semver-patch' || + steps.metadata.outputs.update-type == 'version-update:semver-minor' run: gh pr merge --auto --squash "$PR_URL" env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} From 6b8ccf6cb0db0185bdf92045dcc5a07d19bca37f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 25 Aug 2026 05:00:09 +0000 Subject: [PATCH 27/57] Bump github/codeql-action from 4.37.6 to 4.37.8 (#269) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.6 to 4.37.8. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/v4.37.6...v4.37.8) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jon Fairbanks --- .github/workflows/codeql.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 07f40e8..e2e9508 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7.0.1 - - uses: github/codeql-action/init@v4.37.6 + - uses: github/codeql-action/init@v4.37.8 with: languages: javascript-typescript - - uses: github/codeql-action/analyze@v4.37.6 + - uses: github/codeql-action/analyze@v4.37.8 From e2a6e0dd094ec2af98a5581b958b9c36cf258430 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Tue, 25 Aug 2026 21:20:07 -0700 Subject: [PATCH 28/57] Lower default memory request --- chart/Chart.yaml | 2 +- chart/values.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 3f8e473..714f72e 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.5 +version: 3.0.6 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/chart/values.yaml b/chart/values.yaml index b43d936..6d72179 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -53,7 +53,7 @@ ingress: resources: requests: cpu: 10m - memory: 128Mi + memory: 64Mi limits: memory: 192Mi From cef28c81553d251bd608adc82444591f89e2c193 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Tue, 25 Aug 2026 21:23:25 -0700 Subject: [PATCH 29/57] Harden GitHub Actions workflows --- .github/workflows/ci.yaml | 20 ++++++++++---------- .github/workflows/codeql.yml | 6 +++--- .github/workflows/snyk.yml | 6 ++++-- 3 files changed, 17 insertions(+), 15 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 3bbda41..4de9a96 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -22,8 +22,8 @@ jobs: matrix: node-version: [26] steps: - - uses: actions/checkout@v7.0.1 - - uses: actions/setup-node@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: ${{ matrix.node-version }} cache: npm @@ -34,8 +34,8 @@ jobs: name: Lint and audit runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7.0.1 - - uses: actions/setup-node@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 26 cache: npm @@ -47,8 +47,8 @@ jobs: name: Helm lint and render runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7.0.1 - - uses: azure/setup-helm@v5 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 - run: helm lint chart - run: helm template docker-node-app chart --set autoscaling.enabled=true --set ingress.enabled=true @@ -56,10 +56,10 @@ jobs: name: Build container runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7.0.1 - - uses: docker/setup-buildx-action@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - name: Build test target - uses: docker/build-push-action@v7 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . target: test @@ -67,7 +67,7 @@ jobs: cache-from: type=gha,scope=test cache-to: type=gha,mode=max,scope=test - name: Build production target - uses: docker/build-push-action@v7 + uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: . target: production diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index e2e9508..dcc4d5c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -17,8 +17,8 @@ jobs: name: Analyze JavaScript runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7.0.1 - - uses: github/codeql-action/init@v4.37.8 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 with: languages: javascript-typescript - - uses: github/codeql-action/analyze@v4.37.8 + - uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index 1373962..9df2891 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -28,9 +28,11 @@ jobs: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} steps: - - name: Check Snyk configuration + - name: Require Snyk configuration if: env.SNYK_TOKEN == '' - run: echo "::warning::SNYK_TOKEN is not configured; skipping Snyk scan." + run: | + echo "::error::SNYK_TOKEN is not configured." + exit 1 - name: Checkout if: env.SNYK_TOKEN != '' From 872a958e402571dbc08330ca8ce16c59834b5f67 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Tue, 25 Aug 2026 21:25:14 -0700 Subject: [PATCH 30/57] Restore optional Snyk configuration --- .github/workflows/snyk.yml | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index 9df2891..1373962 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -28,11 +28,9 @@ jobs: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} steps: - - name: Require Snyk configuration + - name: Check Snyk configuration if: env.SNYK_TOKEN == '' - run: | - echo "::error::SNYK_TOKEN is not configured." - exit 1 + run: echo "::warning::SNYK_TOKEN is not configured; skipping Snyk scan." - name: Checkout if: env.SNYK_TOKEN != '' From b169ffd59087dca3cd441e244117701b10a4668f Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Tue, 25 Aug 2026 22:17:01 -0700 Subject: [PATCH 31/57] Tune Docker Node App readiness delay --- chart/Chart.yaml | 2 +- chart/values.yaml | 5 ++++- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 714f72e..6211241 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.6 +version: 3.0.7 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/chart/values.yaml b/chart/values.yaml index 6d72179..c72c71a 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -68,7 +68,10 @@ readinessProbe: httpGet: path: /healthz port: http - initialDelaySeconds: 2 + # HPA scale-outs showed a few connection-refused checks at two seconds; + # three seconds gives the Node listener time to bind without delaying traffic + # once the pod is actually ready. + initialDelaySeconds: 3 periodSeconds: 5 autoscaling: From c8d85cdb397edb2314f697b64aaf5985653d7baa Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Tue, 25 Aug 2026 22:24:26 -0700 Subject: [PATCH 32/57] Remove readiness delay comment --- chart/values.yaml | 3 --- 1 file changed, 3 deletions(-) diff --git a/chart/values.yaml b/chart/values.yaml index c72c71a..a599217 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -68,9 +68,6 @@ readinessProbe: httpGet: path: /healthz port: http - # HPA scale-outs showed a few connection-refused checks at two seconds; - # three seconds gives the Node listener time to bind without delaying traffic - # once the pod is actually ready. initialDelaySeconds: 3 periodSeconds: 5 From f1a504736ddcc878bf7340da563b475b0e0e0f3d Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Wed, 26 Aug 2026 19:33:22 -0700 Subject: [PATCH 33/57] Add shutdown readiness handling --- __tests__/app.test.js | 11 ++++++++++- app.js | 16 ++++++++++++++-- chart/values.yaml | 2 +- index.js | 13 ++++++++++--- 4 files changed, 35 insertions(+), 7 deletions(-) diff --git a/__tests__/app.test.js b/__tests__/app.test.js index 71caeb5..f8c92db 100644 --- a/__tests__/app.test.js +++ b/__tests__/app.test.js @@ -1,9 +1,11 @@ const assert = require('node:assert/strict'); const { describe, test } = require('node:test'); const request = require('supertest'); -const app = require('../app'); +const { app, setDraining } = require('../app'); describe('Verify the site loads', () => { + test.after(() => setDraining(false)); + test('Response should equal HTTP 200', async () => { const response = await request(app).get('/'); assert.equal(response.statusCode, 200); @@ -14,4 +16,11 @@ describe('Verify the site loads', () => { assert.equal(response.statusCode, 200); assert.match(response.body.response.msg, /up and running/); }); + + test('Readiness check rejects traffic while draining', async () => { + assert.equal((await request(app).get('/readyz')).statusCode, 200); + + setDraining(true); + assert.equal((await request(app).get('/readyz')).statusCode, 503); + }); }); diff --git a/app.js b/app.js index f0ea584..d8faa3a 100644 --- a/app.js +++ b/app.js @@ -4,6 +4,7 @@ const app = express(); const os = require('os'); const dayjs = require('dayjs'); const advancedFormat = require('dayjs/plugin/advancedFormat'); +let isDraining = false; app.set('view engine', 'ejs'); dayjs.extend(advancedFormat); @@ -49,7 +50,18 @@ app.get('/healthz', (req, res) => { host: os.hostname(), clientSourceIP: ip, }, - }); + }); +}); + +// During termination, keep the container alive long enough for in-flight +// requests to finish, but tell Kubernetes and load balancers not to send it +// any new requests. +app.get('/readyz', (_req, res) => { + res.sendStatus(isDraining ? 503 : 200); }); -module.exports = app; +function setDraining(value) { + isDraining = value; +} + +module.exports = { app, setDraining }; diff --git a/chart/values.yaml b/chart/values.yaml index a599217..90c73b9 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -66,7 +66,7 @@ livenessProbe: readinessProbe: httpGet: - path: /healthz + path: /readyz port: http initialDelaySeconds: 3 periodSeconds: 5 diff --git a/index.js b/index.js index ea32424..c9657a7 100644 --- a/index.js +++ b/index.js @@ -4,7 +4,7 @@ const SHUTDOWN_TIMEOUT_MS = Number.parseInt( process.env.SHUTDOWN_TIMEOUT_MS || '25000', 10, ); -const app = require('./app'); +const { app, setDraining } = require('./app'); function startServer({ port = PORT, host = '0.0.0.0', logger = console } = {}) { return app.listen(port, host, () => { @@ -14,7 +14,11 @@ function startServer({ port = PORT, host = '0.0.0.0', logger = console } = {}) { function createGracefulShutdown( server, - { timeoutMs = SHUTDOWN_TIMEOUT_MS, logger = console } = {}, + { + timeoutMs = SHUTDOWN_TIMEOUT_MS, + logger = console, + onShutdownStart = () => {}, + } = {}, ) { let shutdownPromise; @@ -24,6 +28,7 @@ function createGracefulShutdown( } logger.log(`Received ${signal}; draining active connections...`); + onShutdownStart(); shutdownPromise = new Promise((resolve, reject) => { const timeout = setTimeout(() => { logger.error(`Graceful shutdown exceeded ${timeoutMs}ms; forcing close.`); @@ -49,7 +54,9 @@ function createGracefulShutdown( if (require.main === module) { const server = startServer(); - const shutdown = createGracefulShutdown(server); + const shutdown = createGracefulShutdown(server, { + onShutdownStart: () => setDraining(true), + }); for (const signal of ['SIGTERM', 'SIGINT']) { process.once(signal, () => { From 5a408440b69190c8eaac4aa9ab0c68e8aaccc920 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Wed, 26 Aug 2026 19:42:28 -0700 Subject: [PATCH 34/57] Bump chart version to 3.0.8 --- chart/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 6211241..8854b71 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.7 +version: 3.0.8 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to From 0ae24aa897e5013d199b63345a258f59cf7a0e8d Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Wed, 26 Aug 2026 20:27:55 -0700 Subject: [PATCH 35/57] Deploy Docker Node App with immutable image tags --- .github/workflows/publish.yaml | 9 ++++----- chart/Chart.yaml | 4 ++-- chart/values.yaml | 2 ++ package-lock.json | 4 ++-- package.json | 2 +- 5 files changed, 11 insertions(+), 10 deletions(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 9ac7fd8..c2dd622 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -31,19 +31,15 @@ jobs: with: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_ACCESS_TOKEN }} - - name: Read package version - id: package - run: echo "version=$(jq -r .version package.json)" >> "$GITHUB_OUTPUT" - name: Generate image metadata id: meta uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6 with: images: jonfairbanks/docker-node-app tags: | - type=sha + type=sha,format=long type=raw,value=develop,enable=${{ github.event.workflow_run.head_branch == 'develop' }} type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'master' }} - type=raw,value=${{ steps.package.outputs.version }},enable=${{ github.event.workflow_run.head_branch == 'master' }} - name: Build and push uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7 with: @@ -87,5 +83,8 @@ jobs: exit 1 fi echo "$GHCR_TOKEN" | helm registry login ghcr.io --username "$GITHUB_ACTOR" --password-stdin + image_tag="sha-${{ github.event.workflow_run.head_sha }}" + sed -i "s/^ tag: \"\"$/ tag: \"${image_tag}\"/" chart/values.yaml + grep -F "tag: \"${image_tag}\"" chart/values.yaml helm package chart --destination /tmp/charts helm push "/tmp/charts/docker-node-app-${version}.tgz" oci://ghcr.io/jonfairbanks/charts diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 8854b71..96282d4 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,9 +16,9 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.8 +version: 3.0.9 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to # follow Semantic Versioning. They should reflect the version the application is using. -appVersion: "3.0.0" +appVersion: "3.0.1" diff --git a/chart/values.yaml b/chart/values.yaml index 90c73b9..28827df 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -3,6 +3,8 @@ replicaCount: 3 image: repository: jonfairbanks/docker-node-app pullPolicy: IfNotPresent + # CI replaces the default with the immutable full-commit image tag before + # publishing the chart. It can be overridden for local development. tag: "" imagePullSecrets: [] diff --git a/package-lock.json b/package-lock.json index 1508c81..571fe2f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "docker-node-app", - "version": "3.0.0", + "version": "3.0.1", "lockfileVersion": 2, "requires": true, "packages": { "": { "name": "docker-node-app", - "version": "3.0.0", + "version": "3.0.1", "license": "MIT", "dependencies": { "dayjs": "^1.11.23", diff --git a/package.json b/package.json index c3318b7..d159d1a 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "docker-node-app", - "version": "3.0.0", + "version": "3.0.1", "description": "Node.js on Docker", "repository": "https://github.com/jonfairbanks/docker-node-app.git", "main": "index.js", From 320b16f1be8d5f40cece8297b88bc92540ad8d4f Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Wed, 26 Aug 2026 20:31:18 -0700 Subject: [PATCH 36/57] Restore version-tagged Docker Node App releases --- .github/workflows/publish.yaml | 9 +++++---- chart/Chart.yaml | 2 +- chart/values.yaml | 2 -- 3 files changed, 6 insertions(+), 7 deletions(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index c2dd622..9ac7fd8 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -31,15 +31,19 @@ jobs: with: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_ACCESS_TOKEN }} + - name: Read package version + id: package + run: echo "version=$(jq -r .version package.json)" >> "$GITHUB_OUTPUT" - name: Generate image metadata id: meta uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6 with: images: jonfairbanks/docker-node-app tags: | - type=sha,format=long + type=sha type=raw,value=develop,enable=${{ github.event.workflow_run.head_branch == 'develop' }} type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'master' }} + type=raw,value=${{ steps.package.outputs.version }},enable=${{ github.event.workflow_run.head_branch == 'master' }} - name: Build and push uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7 with: @@ -83,8 +87,5 @@ jobs: exit 1 fi echo "$GHCR_TOKEN" | helm registry login ghcr.io --username "$GITHUB_ACTOR" --password-stdin - image_tag="sha-${{ github.event.workflow_run.head_sha }}" - sed -i "s/^ tag: \"\"$/ tag: \"${image_tag}\"/" chart/values.yaml - grep -F "tag: \"${image_tag}\"" chart/values.yaml helm package chart --destination /tmp/charts helm push "/tmp/charts/docker-node-app-${version}.tgz" oci://ghcr.io/jonfairbanks/charts diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 96282d4..058db5e 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.9 +version: 3.0.10 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/chart/values.yaml b/chart/values.yaml index 28827df..90c73b9 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -3,8 +3,6 @@ replicaCount: 3 image: repository: jonfairbanks/docker-node-app pullPolicy: IfNotPresent - # CI replaces the default with the immutable full-commit image tag before - # publishing the chart. It can be overridden for local development. tag: "" imagePullSecrets: [] From e5f337a8b9a4839edfb6f6d7dcf361e6a4dd9eb8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 28 Aug 2026 05:44:40 +0000 Subject: [PATCH 37/57] Bump eslint from 10.8.1 to 10.9.1 in the npm group (#278) Bumps the npm group with 1 update: [eslint](https://github.com/eslint/eslint). Updates `eslint` from 10.8.1 to 10.9.1 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v10.8.1...v10.9.1) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.9.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 14 +++++++------- package.json | 2 +- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/package-lock.json b/package-lock.json index 571fe2f..0ad3908 100644 --- a/package-lock.json +++ b/package-lock.json @@ -15,7 +15,7 @@ }, "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.8.1", + "eslint": "^10.9.1", "globals": "^17.11.0", "supertest": "^7.2.2" }, @@ -681,9 +681,9 @@ "license": "MIT" }, "node_modules/eslint": { - "version": "10.8.1", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.1.tgz", - "integrity": "sha512-wqA7W2jbsC/BnV9Iv1UZpKVFkO1AdNoSmYW8NWG4HNOBbkAMvIqDZ27pI2f07dqn583NcIC44ckjAcOXDL1QbQ==", + "version": "10.9.1", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.9.1.tgz", + "integrity": "sha512-9VaAkDURekixUQJy0oJYl2DcN6oKMfxay7XzaGYAWQwsb6qfKf+x76R2k1L8kb1boc+FyCAaTA9GmiKaaiaF+A==", "dev": true, "license": "MIT", "workspaces": [ @@ -2421,9 +2421,9 @@ "integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==" }, "eslint": { - "version": "10.8.1", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.8.1.tgz", - "integrity": "sha512-wqA7W2jbsC/BnV9Iv1UZpKVFkO1AdNoSmYW8NWG4HNOBbkAMvIqDZ27pI2f07dqn583NcIC44ckjAcOXDL1QbQ==", + "version": "10.9.1", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.9.1.tgz", + "integrity": "sha512-9VaAkDURekixUQJy0oJYl2DcN6oKMfxay7XzaGYAWQwsb6qfKf+x76R2k1L8kb1boc+FyCAaTA9GmiKaaiaF+A==", "dev": true, "requires": { "@eslint-community/eslint-utils": "^4.8.0", diff --git a/package.json b/package.json index d159d1a..165cca9 100644 --- a/package.json +++ b/package.json @@ -25,7 +25,7 @@ "license": "MIT", "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.8.1", + "eslint": "^10.9.1", "globals": "^17.11.0", "supertest": "^7.2.2" } From e3f7f5950e7ad5102c316cf38eb287b3927a3f53 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 31 Aug 2026 22:10:03 +0000 Subject: [PATCH 38/57] Bump docker/setup-buildx-action from 4.2.0 to 4.3.0 (#279) Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.2.0 to 4.3.0. - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/v4.2.0...37fe631027851001ddb9b187196cc803df7f5f0e) --- updated-dependencies: - dependency-name: docker/setup-buildx-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jon Fairbanks --- .github/workflows/publish.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 9ac7fd8..0bd3496 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -25,7 +25,7 @@ jobs: - name: Set up QEMU uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4 + uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4 - name: Log in to Docker Hub uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 with: From 443ba4f7e095f86e4d1524c66493f23aa73deb8c Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Mon, 31 Aug 2026 15:15:03 -0700 Subject: [PATCH 39/57] fix: dispatch publish after dependabot merge (#280) --- .github/workflows/dependabot-auto-merge.yml | 21 ++++++++++++++++++++- .github/workflows/publish.yaml | 19 ++++++++++++------- 2 files changed, 32 insertions(+), 8 deletions(-) diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index cc21112..b03c8ac 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -2,7 +2,7 @@ name: Dependabot Auto Merge on: pull_request_target: - types: [opened, synchronize, reopened, ready_for_review] + types: [opened, synchronize, reopened, ready_for_review, closed] permissions: contents: write @@ -11,6 +11,7 @@ permissions: jobs: enable-automerge: if: > + github.event.action != 'closed' && github.event.pull_request.user.login == 'dependabot[bot]' && startsWith(github.event.pull_request.head.ref, 'dependabot/') && github.event.pull_request.head.repo.full_name == github.repository && @@ -31,3 +32,21 @@ jobs: env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} PR_URL: ${{ github.event.pull_request.html_url }} + + publish-after-merged-dependabot: + if: > + github.event.action == 'closed' && + github.event.pull_request.merged == true && + github.event.pull_request.base.ref == 'master' && + github.event.pull_request.user.login == 'dependabot[bot]' && + startsWith(github.event.pull_request.head.ref, 'dependabot/') && + github.event.pull_request.head.repo.full_name == github.repository + permissions: + actions: write + contents: read + runs-on: ubuntu-latest + steps: + - name: Dispatch publication from the merged master revision + run: gh workflow run publish.yaml --ref master + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 0bd3496..11793e9 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -1,6 +1,7 @@ name: Publish on: + workflow_dispatch: workflow_run: workflows: [CI] types: [completed] @@ -16,12 +17,14 @@ concurrency: jobs: container: name: Publish container - if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' + if: > + github.event_name == 'workflow_dispatch' || + (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push') runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - ref: ${{ github.event.workflow_run.head_sha }} + ref: ${{ github.event_name == 'workflow_dispatch' && github.sha || github.event.workflow_run.head_sha }} - name: Set up QEMU uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4 - name: Set up Docker Buildx @@ -41,9 +44,9 @@ jobs: images: jonfairbanks/docker-node-app tags: | type=sha - type=raw,value=develop,enable=${{ github.event.workflow_run.head_branch == 'develop' }} - type=raw,value=latest,enable=${{ github.event.workflow_run.head_branch == 'master' }} - type=raw,value=${{ steps.package.outputs.version }},enable=${{ github.event.workflow_run.head_branch == 'master' }} + type=raw,value=develop,enable=${{ (github.event_name == 'workflow_dispatch' && github.ref_name == 'develop') || github.event.workflow_run.head_branch == 'develop' }} + type=raw,value=latest,enable=${{ (github.event_name == 'workflow_dispatch' && github.ref_name == 'master') || github.event.workflow_run.head_branch == 'master' }} + type=raw,value=${{ steps.package.outputs.version }},enable=${{ (github.event_name == 'workflow_dispatch' && github.ref_name == 'master') || github.event.workflow_run.head_branch == 'master' }} - name: Build and push uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7 with: @@ -58,7 +61,9 @@ jobs: helm: name: Publish Helm chart - if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' && github.event.workflow_run.head_branch == 'master' + if: > + (github.event_name == 'workflow_dispatch' && github.ref_name == 'master') || + (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' && github.event.workflow_run.head_branch == 'master') runs-on: ubuntu-latest permissions: contents: read @@ -66,7 +71,7 @@ jobs: steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - ref: ${{ github.event.workflow_run.head_sha }} + ref: ${{ github.event_name == 'workflow_dispatch' && github.sha || github.event.workflow_run.head_sha }} fetch-depth: 2 - name: Set up Helm uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 From db12ea52769ef6cae723cdd0ccc55e958088d71f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 3 Sep 2026 10:24:32 +0000 Subject: [PATCH 40/57] Bump qs from 6.15.3 to 6.16.0 (#281) Bumps [qs](https://github.com/ljharb/qs) from 6.15.3 to 6.16.0. - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](https://github.com/ljharb/qs/compare/v6.15.3...v6.16.0) --- updated-dependencies: - dependency-name: qs dependency-version: 6.16.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/package-lock.json b/package-lock.json index 0ad3908..8a84370 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1623,9 +1623,9 @@ } }, "node_modules/qs": { - "version": "6.15.3", - "resolved": "https://registry.npmjs.org/qs/-/qs-6.15.3.tgz", - "integrity": "sha512-O9gl3zCl5h5blw1KGUzQKhA5oUXSl8rwUIM5o0S3nCXMliSvy5Dzx7/DJcI+SwgICv+IneSZwhBh1oSyEHA71A==", + "version": "6.16.0", + "resolved": "https://registry.npmjs.org/qs/-/qs-6.16.0.tgz", + "integrity": "sha512-h6fhOIaRrID2CbEY2fqs+7t+UXZo+MLAnU5gRIq85uFtdiUPCdsApMlHhXogKVM4HM2DVbIjGNTTYH2OcmP1vA==", "license": "BSD-3-Clause", "dependencies": { "es-define-property": "^1.0.1", @@ -3037,9 +3037,9 @@ "dev": true }, "qs": { - "version": "6.15.3", - "resolved": "https://registry.npmjs.org/qs/-/qs-6.15.3.tgz", - "integrity": "sha512-O9gl3zCl5h5blw1KGUzQKhA5oUXSl8rwUIM5o0S3nCXMliSvy5Dzx7/DJcI+SwgICv+IneSZwhBh1oSyEHA71A==", + "version": "6.16.0", + "resolved": "https://registry.npmjs.org/qs/-/qs-6.16.0.tgz", + "integrity": "sha512-h6fhOIaRrID2CbEY2fqs+7t+UXZo+MLAnU5gRIq85uFtdiUPCdsApMlHhXogKVM4HM2DVbIjGNTTYH2OcmP1vA==", "requires": { "es-define-property": "^1.0.1", "side-channel": "^1.1.1" From 5ced862bb1be694c0f709e027021562530f27069 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 4 Sep 2026 05:50:23 +0000 Subject: [PATCH 41/57] Bump docker/setup-qemu-action from 4.2.0 to 4.3.0 (#283) Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 4.2.0 to 4.3.0. - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](https://github.com/docker/setup-qemu-action/compare/96fe6ef7f33517b61c61be40b68a1882f3264fb8...1f40c72289eff860ee54a304f1438e3cff362e0a) --- updated-dependencies: - dependency-name: docker/setup-qemu-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/publish.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 11793e9..9dbda74 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -26,7 +26,7 @@ jobs: with: ref: ${{ github.event_name == 'workflow_dispatch' && github.sha || github.event.workflow_run.head_sha }} - name: Set up QEMU - uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4 + uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4 - name: Log in to Docker Hub From 91ae2e824e842579faac628ab60d100a48d0e37e Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 4 Sep 2026 05:57:25 +0000 Subject: [PATCH 42/57] Bump github/codeql-action/init from 4.37.8 to 4.37.9 (#284) Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.8 to 4.37.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28...cdf488f595d80d6e07e03d4674febd5ab45fa938) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index dcc4d5c..c5e89ba 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 + - uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: languages: javascript-typescript - uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 From 12eab7b05303f7aa369a10d5c5ffcfabfd37104f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 4 Sep 2026 06:04:55 +0000 Subject: [PATCH 43/57] Bump github/codeql-action/analyze from 4.37.8 to 4.37.9 (#282) Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.8 to 4.37.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28...cdf488f595d80d6e07e03d4674febd5ab45fa938) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index c5e89ba..f72fcd9 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -21,4 +21,4 @@ jobs: - uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: languages: javascript-typescript - - uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 + - uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 From cbfe03844421fa567d6aff9e777f6b45b038015f Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Wed, 9 Sep 2026 22:29:40 -0700 Subject: [PATCH 44/57] Add configurable HPA behavior (#285) * feat: support HPA behavior configuration * fix: use current Snyk container command --- .github/workflows/snyk.yml | 21 ++++++++++++++------- chart/Chart.yaml | 2 +- chart/templates/hpa.yaml | 4 ++++ chart/values.yaml | 3 +++ 4 files changed, 22 insertions(+), 8 deletions(-) diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index 1373962..a5f19a5 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -62,10 +62,17 @@ jobs: - name: Scan production image if: env.SNYK_TOKEN != '' - uses: snyk/actions/docker@9adf32b1121593767fc3c057af55b55db032dc04 # v1.0.0 - with: - image: docker-node-app:snyk - args: >- - --exclude-app-vulns - --file=Dockerfile - --severity-threshold=high + run: | + # snyk/actions/docker invokes the legacy `snyk test --docker` path. + # Use Snyk's current container command with the current immutable + # scanner runtime so scanner updates cannot silently change CI. + docker run --rm \ + --env SNYK_TOKEN \ + --volume /var/run/docker.sock:/var/run/docker.sock \ + --volume "$GITHUB_WORKSPACE:/workspace" \ + --workdir /workspace \ + snyk/snyk@sha256:3c6fbd3e70dea2792d6bc2a080335fafdccd243ad9c0b7faa91002caac7d7851 \ + snyk container test docker-node-app:snyk \ + --exclude-app-vulns \ + --file=Dockerfile \ + --severity-threshold=high diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 058db5e..26c8035 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -16,7 +16,7 @@ kubeVersion: ">=1.25.0-0" # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 3.0.10 +version: 3.0.11 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/chart/templates/hpa.yaml b/chart/templates/hpa.yaml index 3a9068c..99068a6 100644 --- a/chart/templates/hpa.yaml +++ b/chart/templates/hpa.yaml @@ -29,4 +29,8 @@ spec: type: Utilization averageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }} {{- end }} + {{- with .Values.autoscaling.behavior }} + behavior: + {{- toYaml . | nindent 4 }} + {{- end }} {{- end }} diff --git a/chart/values.yaml b/chart/values.yaml index 90c73b9..f7a4e15 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -77,6 +77,9 @@ autoscaling: maxReplicas: 10 targetCPUUtilizationPercentage: 70 targetMemoryUtilizationPercentage: "" + # Optional autoscaling/v2 behavior, passed through unchanged when set. + # Leave empty to use Kubernetes defaults. + behavior: {} podDisruptionBudget: enabled: true From 177ecbfbf0413eb351777f9d82a971db102cdfc5 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 11 Sep 2026 05:43:58 +0000 Subject: [PATCH 45/57] Bump the npm group with 2 updates (#286) Bumps the npm group with 2 updates: [eslint](https://github.com/eslint/eslint) and [globals](https://github.com/sindresorhus/globals). Updates `eslint` from 10.9.1 to 10.10.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v10.9.1...v10.10.0) Updates `globals` from 17.11.0 to 17.12.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](https://github.com/sindresorhus/globals/compare/v17.11.0...v17.12.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.10.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: globals dependency-version: 17.12.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 318 +++++++++++++++++++++++++++++++++++----------- package.json | 4 +- 2 files changed, 245 insertions(+), 77 deletions(-) diff --git a/package-lock.json b/package-lock.json index 8a84370..c7c547e 100644 --- a/package-lock.json +++ b/package-lock.json @@ -15,8 +15,8 @@ }, "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.9.1", - "globals": "^17.11.0", + "eslint": "^10.10.0", + "globals": "^17.12.0", "supertest": "^7.2.2" }, "engines": { @@ -24,6 +24,30 @@ "npm": ">=10" } }, + "node_modules/@cacheable/memory": { + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/@cacheable/memory/-/memory-2.2.0.tgz", + "integrity": "sha512-CTLKqLItRCEixEAewD3/j9DB3/o96gpTPD4eJ1v+DGOlxZRZncRQkGYqqnAGCscYd6RNeXfGeiuCphsPtqyIfQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@cacheable/utils": "^2.5.0", + "@keyv/bigmap": "^1.3.1", + "hookified": "^1.15.1", + "keyv": "^5.6.0" + } + }, + "node_modules/@cacheable/utils": { + "version": "2.5.0", + "resolved": "https://registry.npmjs.org/@cacheable/utils/-/utils-2.5.0.tgz", + "integrity": "sha512-buipgOVDkkPXNR5+xBpDw7Zk2n1EvU7qBJCNUcL7rhQ//kfpOXPAvQ511Os0vpLYJ1pZnvudNytkQt2hst3wqA==", + "dev": true, + "license": "MIT", + "dependencies": { + "hashery": "^1.5.1", + "keyv": "^5.6.0" + } + }, "node_modules/@eslint-community/eslint-utils": { "version": "4.9.1", "resolved": "https://registry.npmjs.org/@eslint-community/eslint-utils/-/eslint-utils-4.9.1.tgz", @@ -155,9 +179,9 @@ } }, "node_modules/@eslint/plugin-kit": { - "version": "0.7.2", - "resolved": "https://registry.npmjs.org/@eslint/plugin-kit/-/plugin-kit-0.7.2.tgz", - "integrity": "sha512-+CNAzxglkrpNf/kKywqQfk74QjtceuOE7Qm+AF8miRvPF/wmmK5+OJOgVh3AVTT3RP2mH3+FOaxlE5v72owk0A==", + "version": "0.7.3", + "resolved": "https://registry.npmjs.org/@eslint/plugin-kit/-/plugin-kit-0.7.3.tgz", + "integrity": "sha512-IkO+/KEUvwbVpiURZg+P7zF74z5Jxe0UgJxVni+RtoHQ6IZieXaO02kmadomap/q+l6bc/jdPGGqTjhuZnuz1Q==", "dev": true, "license": "Apache-2.0", "dependencies": { @@ -233,6 +257,30 @@ "url": "https://github.com/sponsors/nzakas" } }, + "node_modules/@keyv/bigmap": { + "version": "1.3.1", + "resolved": "https://registry.npmjs.org/@keyv/bigmap/-/bigmap-1.3.1.tgz", + "integrity": "sha512-WbzE9sdmQtKy8vrNPa9BRnwZh5UF4s1KTmSK0KUVLo3eff5BlQNNWDnFOouNpKfPKDnms9xynJjsMYjMaT/aFQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "hashery": "^1.4.0", + "hookified": "^1.15.0" + }, + "engines": { + "node": ">= 18" + }, + "peerDependencies": { + "keyv": "^5.6.0" + } + }, + "node_modules/@keyv/serialize": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/@keyv/serialize/-/serialize-1.1.1.tgz", + "integrity": "sha512-dXn3FZhPv0US+7dtJsIi2R+c7qWYiReoEh5zUntWCf4oSpMNib8FDhSoed6m3QyZdx5hK7iLFkYk3rNxwt8vTA==", + "dev": true, + "license": "MIT" + }, "node_modules/@noble/hashes": { "version": "1.8.0", "resolved": "https://registry.npmjs.org/@noble/hashes/-/hashes-1.8.0.tgz", @@ -413,6 +461,20 @@ "node": ">= 0.8" } }, + "node_modules/cacheable": { + "version": "2.5.0", + "resolved": "https://registry.npmjs.org/cacheable/-/cacheable-2.5.0.tgz", + "integrity": "sha512-60cyAOytib/OzBw1JNSoSV/boK1AtHryDIjvVBk7XbN4ugfkM3+Sry7fEjNgPMGgOjuaZPAp8ruZ0Cxafwyq9g==", + "dev": true, + "license": "MIT", + "dependencies": { + "@cacheable/memory": "^2.2.0", + "@cacheable/utils": "^2.5.0", + "hookified": "^1.15.0", + "keyv": "^5.6.0", + "qified": "^0.10.1" + } + }, "node_modules/call-bind-apply-helpers": { "version": "1.0.2", "resolved": "https://registry.npmjs.org/call-bind-apply-helpers/-/call-bind-apply-helpers-1.0.2.tgz", @@ -681,9 +743,9 @@ "license": "MIT" }, "node_modules/eslint": { - "version": "10.9.1", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.9.1.tgz", - "integrity": "sha512-9VaAkDURekixUQJy0oJYl2DcN6oKMfxay7XzaGYAWQwsb6qfKf+x76R2k1L8kb1boc+FyCAaTA9GmiKaaiaF+A==", + "version": "10.10.0", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.10.0.tgz", + "integrity": "sha512-NPXn6r5zl4uET1DAVPaOwzX3rut4c0wcmw3dWJAfOsTM5+TogXo0DDjz8pwm/hL8cyVNpHqeK4JpN0NjnyFFNw==", "dev": true, "license": "MIT", "workspaces": [ @@ -695,7 +757,7 @@ "@eslint/config-array": "^0.23.5", "@eslint/config-helpers": "^0.7.0", "@eslint/core": "^1.2.1", - "@eslint/plugin-kit": "^0.7.2", + "@eslint/plugin-kit": "^0.7.3", "@humanfs/node": "^0.16.6", "@humanwhocodes/module-importer": "^1.0.1", "@humanwhocodes/retry": "^0.4.2", @@ -710,7 +772,7 @@ "esquery": "^1.7.0", "esutils": "^2.0.2", "fast-deep-equal": "^3.1.3", - "file-entry-cache": "^8.0.0", + "file-entry-cache": "11.1.5 || >11.1.6 <12", "find-up": "^5.0.0", "glob-parent": "^6.0.2", "ignore": "^5.2.0", @@ -955,16 +1017,13 @@ "license": "MIT" }, "node_modules/file-entry-cache": { - "version": "8.0.0", - "resolved": "https://registry.npmjs.org/file-entry-cache/-/file-entry-cache-8.0.0.tgz", - "integrity": "sha512-XXTUwCvisa5oacNGRP9SfNtYBNAMi+RPwBFmblZEF7N7swHYQS6/Zfk7SRwx4D5j3CH211YNRco1DEMNVfZCnQ==", + "version": "11.1.5", + "resolved": "https://registry.npmjs.org/file-entry-cache/-/file-entry-cache-11.1.5.tgz", + "integrity": "sha512-+PFTHITI08JIGhnNpGNI8T8inUpgZfk3GNEqfT9R2zZV2iFXg3CvqzSl/uEhs7TSGujYRELEANyDvS8Fj7+S7Q==", "dev": true, "license": "MIT", "dependencies": { - "flat-cache": "^4.0.0" - }, - "engines": { - "node": ">=16.0.0" + "flat-cache": "^6.1.23" } }, "node_modules/finalhandler": { @@ -1005,23 +1064,21 @@ } }, "node_modules/flat-cache": { - "version": "4.0.1", - "resolved": "https://registry.npmjs.org/flat-cache/-/flat-cache-4.0.1.tgz", - "integrity": "sha512-f7ccFPK3SXFHpx15UIGyRJ/FJQctuKZ0zVuN3frBo4HnK3cay9VEW0R6yPYFHC0AgqhukPzKjq22t5DmAyqGyw==", + "version": "6.1.23", + "resolved": "https://registry.npmjs.org/flat-cache/-/flat-cache-6.1.23.tgz", + "integrity": "sha512-f++BY9pTk+983xK1FLzlLpmM0i0z+jHmx3QESGkURMXujQZz1k5wzwX6hjnQ8goaD0B+sYnDK1yZ6MTyZfUaqA==", "dev": true, "license": "MIT", "dependencies": { - "flatted": "^3.2.9", - "keyv": "^4.5.4" - }, - "engines": { - "node": ">=16" + "cacheable": "^2.5.0", + "flatted": "^3.4.2", + "hookified": "^1.15.0" } }, "node_modules/flatted": { - "version": "3.4.2", - "resolved": "https://registry.npmjs.org/flatted/-/flatted-3.4.2.tgz", - "integrity": "sha512-PjDse7RzhcPkIJwy5t7KPWQSZ9cAbzQXcafsetQoD7sOJRQlGikNbx7yZp2OotDnJyrDcbyRq3Ttb18iYOqkxA==", + "version": "3.4.4", + "resolved": "https://registry.npmjs.org/flatted/-/flatted-3.4.4.tgz", + "integrity": "sha512-5+ybhBZANEJxaH3X5evAFatUxLfEHSr7n6kYJ+1Qd0mUqr4eu9gIf6GDbWHf8RJijHrjjO8G+la14SlL2SeS1Q==", "dev": true, "license": "ISC" }, @@ -1147,9 +1204,9 @@ } }, "node_modules/globals": { - "version": "17.11.0", - "resolved": "https://registry.npmjs.org/globals/-/globals-17.11.0.tgz", - "integrity": "sha512-Z2I8hM+PbJDXQDq3Icgpzv+mPdwr68iZUU9d5WW4FuXfDUQfkZaZuvjMv42/5crNyw154+9+VWXbYrUgDXbxNw==", + "version": "17.12.0", + "resolved": "https://registry.npmjs.org/globals/-/globals-17.12.0.tgz", + "integrity": "sha512-cezEd/DTyyht9cvSSURyygXPfy04GtWO/5e6ZPvH7fCtjKz9PYOmuawphw1Ctd1f6C+5JypXfGD7ahNMXvevBA==", "dev": true, "license": "MIT", "engines": { @@ -1199,6 +1256,19 @@ "url": "https://github.com/sponsors/ljharb" } }, + "node_modules/hashery": { + "version": "1.5.1", + "resolved": "https://registry.npmjs.org/hashery/-/hashery-1.5.1.tgz", + "integrity": "sha512-iZyKG96/JwPz1N55vj2Ie2vXbhu440zfUfJvSwEqEbeLluk7NnapfGqa7LH0mOsnDxTF85Mx8/dyR6HfqcbmbQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "hookified": "^1.15.0" + }, + "engines": { + "node": ">=20" + } + }, "node_modules/hasown": { "version": "2.0.4", "resolved": "https://registry.npmjs.org/hasown/-/hasown-2.0.4.tgz", @@ -1211,6 +1281,13 @@ "node": ">= 0.4" } }, + "node_modules/hookified": { + "version": "1.15.1", + "resolved": "https://registry.npmjs.org/hookified/-/hookified-1.15.1.tgz", + "integrity": "sha512-MvG/clsADq1GPM2KGo2nyfaWVyn9naPiXrqIe4jYjXNZQt238kWyOGrsyc/DmRAQ+Re6yeo6yX/yoNCG5KAEVg==", + "dev": true, + "license": "MIT" + }, "node_modules/http-errors": { "version": "2.0.1", "resolved": "https://registry.npmjs.org/http-errors/-/http-errors-2.0.1.tgz", @@ -1314,13 +1391,6 @@ "dev": true, "license": "ISC" }, - "node_modules/json-buffer": { - "version": "3.0.1", - "resolved": "https://registry.npmjs.org/json-buffer/-/json-buffer-3.0.1.tgz", - "integrity": "sha512-4bV5BfR2mqfQTJm+V5tPPdf+ZpuhiIvTuAB5g8kcrXOZpTT/QwwVRWBywX1ozr6lEuPdbHxwaJlm9G6mI2sfSQ==", - "dev": true, - "license": "MIT" - }, "node_modules/json-schema-traverse": { "version": "0.4.1", "resolved": "https://registry.npmjs.org/json-schema-traverse/-/json-schema-traverse-0.4.1.tgz", @@ -1335,13 +1405,13 @@ "dev": true }, "node_modules/keyv": { - "version": "4.5.4", - "resolved": "https://registry.npmjs.org/keyv/-/keyv-4.5.4.tgz", - "integrity": "sha512-oxVHkHR/EJf2CNXnWxRLW6mg7JyCCUcG0DtEGmL2ctUo1PNTin1PUil+r/+4r5MpVgC/fn1kjsx7mjSujKqIpw==", + "version": "5.6.0", + "resolved": "https://registry.npmjs.org/keyv/-/keyv-5.6.0.tgz", + "integrity": "sha512-CYDD3SOtsHtyXeEORYRx2qBtpDJFjRTGXUtmNEMGyzYOKj1TE3tycdlho7kA1Ufx9OYWZzg52QFBGALTirzDSw==", "dev": true, "license": "MIT", "dependencies": { - "json-buffer": "3.0.1" + "@keyv/serialize": "^1.1.1" } }, "node_modules/levn": { @@ -1622,6 +1692,26 @@ "node": ">=6" } }, + "node_modules/qified": { + "version": "0.10.1", + "resolved": "https://registry.npmjs.org/qified/-/qified-0.10.1.tgz", + "integrity": "sha512-+Owyggi9IxT1ePKGafcI87ubSmxol6smwJ+RAHDQlx9+9cPwFWDiKFFCPuWhr9ignlGpZ9vDQLw67N4dcTVFEA==", + "dev": true, + "license": "MIT", + "dependencies": { + "hookified": "^2.1.1" + }, + "engines": { + "node": ">=20" + } + }, + "node_modules/qified/node_modules/hookified": { + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/hookified/-/hookified-2.2.0.tgz", + "integrity": "sha512-p/LgFzRN5FeoD3DLS6bkUapeye6E4SI6yJs6KetENd18S+FBthqYq2amJUWpt5z0EQwwHemidjY5OqJGEKm5uA==", + "dev": true, + "license": "MIT" + }, "node_modules/qs": { "version": "6.16.0", "resolved": "https://registry.npmjs.org/qs/-/qs-6.16.0.tgz", @@ -2004,6 +2094,28 @@ } }, "dependencies": { + "@cacheable/memory": { + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/@cacheable/memory/-/memory-2.2.0.tgz", + "integrity": "sha512-CTLKqLItRCEixEAewD3/j9DB3/o96gpTPD4eJ1v+DGOlxZRZncRQkGYqqnAGCscYd6RNeXfGeiuCphsPtqyIfQ==", + "dev": true, + "requires": { + "@cacheable/utils": "^2.5.0", + "@keyv/bigmap": "^1.3.1", + "hookified": "^1.15.1", + "keyv": "^5.6.0" + } + }, + "@cacheable/utils": { + "version": "2.5.0", + "resolved": "https://registry.npmjs.org/@cacheable/utils/-/utils-2.5.0.tgz", + "integrity": "sha512-buipgOVDkkPXNR5+xBpDw7Zk2n1EvU7qBJCNUcL7rhQ//kfpOXPAvQ511Os0vpLYJ1pZnvudNytkQt2hst3wqA==", + "dev": true, + "requires": { + "hashery": "^1.5.1", + "keyv": "^5.6.0" + } + }, "@eslint-community/eslint-utils": { "version": "4.9.1", "resolved": "https://registry.npmjs.org/@eslint-community/eslint-utils/-/eslint-utils-4.9.1.tgz", @@ -2081,9 +2193,9 @@ "dev": true }, "@eslint/plugin-kit": { - "version": "0.7.2", - "resolved": "https://registry.npmjs.org/@eslint/plugin-kit/-/plugin-kit-0.7.2.tgz", - "integrity": "sha512-+CNAzxglkrpNf/kKywqQfk74QjtceuOE7Qm+AF8miRvPF/wmmK5+OJOgVh3AVTT3RP2mH3+FOaxlE5v72owk0A==", + "version": "0.7.3", + "resolved": "https://registry.npmjs.org/@eslint/plugin-kit/-/plugin-kit-0.7.3.tgz", + "integrity": "sha512-IkO+/KEUvwbVpiURZg+P7zF74z5Jxe0UgJxVni+RtoHQ6IZieXaO02kmadomap/q+l6bc/jdPGGqTjhuZnuz1Q==", "dev": true, "requires": { "@eslint/core": "^1.2.1", @@ -2128,6 +2240,22 @@ "integrity": "sha512-bV0Tgo9K4hfPCek+aMAn81RppFKv2ySDQeMoSZuvTASywNTnVJCArCZE2FWqpvIatKu7VMRLWlR1EazvVhDyhQ==", "dev": true }, + "@keyv/bigmap": { + "version": "1.3.1", + "resolved": "https://registry.npmjs.org/@keyv/bigmap/-/bigmap-1.3.1.tgz", + "integrity": "sha512-WbzE9sdmQtKy8vrNPa9BRnwZh5UF4s1KTmSK0KUVLo3eff5BlQNNWDnFOouNpKfPKDnms9xynJjsMYjMaT/aFQ==", + "dev": true, + "requires": { + "hashery": "^1.4.0", + "hookified": "^1.15.0" + } + }, + "@keyv/serialize": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/@keyv/serialize/-/serialize-1.1.1.tgz", + "integrity": "sha512-dXn3FZhPv0US+7dtJsIi2R+c7qWYiReoEh5zUntWCf4oSpMNib8FDhSoed6m3QyZdx5hK7iLFkYk3rNxwt8vTA==", + "dev": true + }, "@noble/hashes": { "version": "1.8.0", "resolved": "https://registry.npmjs.org/@noble/hashes/-/hashes-1.8.0.tgz", @@ -2250,6 +2378,19 @@ "resolved": "https://registry.npmjs.org/bytes/-/bytes-3.1.2.tgz", "integrity": "sha512-/Nf7TyzTx6S3yRJObOAV7956r8cr2+Oj8AC5dt8wSP3BQAoeX58NoHyCU8P8zGkNXStjTSi6fzO6F0pBdcYbEg==" }, + "cacheable": { + "version": "2.5.0", + "resolved": "https://registry.npmjs.org/cacheable/-/cacheable-2.5.0.tgz", + "integrity": "sha512-60cyAOytib/OzBw1JNSoSV/boK1AtHryDIjvVBk7XbN4ugfkM3+Sry7fEjNgPMGgOjuaZPAp8ruZ0Cxafwyq9g==", + "dev": true, + "requires": { + "@cacheable/memory": "^2.2.0", + "@cacheable/utils": "^2.5.0", + "hookified": "^1.15.0", + "keyv": "^5.6.0", + "qified": "^0.10.1" + } + }, "call-bind-apply-helpers": { "version": "1.0.2", "resolved": "https://registry.npmjs.org/call-bind-apply-helpers/-/call-bind-apply-helpers-1.0.2.tgz", @@ -2421,9 +2562,9 @@ "integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==" }, "eslint": { - "version": "10.9.1", - "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.9.1.tgz", - "integrity": "sha512-9VaAkDURekixUQJy0oJYl2DcN6oKMfxay7XzaGYAWQwsb6qfKf+x76R2k1L8kb1boc+FyCAaTA9GmiKaaiaF+A==", + "version": "10.10.0", + "resolved": "https://registry.npmjs.org/eslint/-/eslint-10.10.0.tgz", + "integrity": "sha512-NPXn6r5zl4uET1DAVPaOwzX3rut4c0wcmw3dWJAfOsTM5+TogXo0DDjz8pwm/hL8cyVNpHqeK4JpN0NjnyFFNw==", "dev": true, "requires": { "@eslint-community/eslint-utils": "^4.8.0", @@ -2431,7 +2572,7 @@ "@eslint/config-array": "^0.23.5", "@eslint/config-helpers": "^0.7.0", "@eslint/core": "^1.2.1", - "@eslint/plugin-kit": "^0.7.2", + "@eslint/plugin-kit": "^0.7.3", "@humanfs/node": "^0.16.6", "@humanwhocodes/module-importer": "^1.0.1", "@humanwhocodes/retry": "^0.4.2", @@ -2446,7 +2587,7 @@ "esquery": "^1.7.0", "esutils": "^2.0.2", "fast-deep-equal": "^3.1.3", - "file-entry-cache": "^8.0.0", + "file-entry-cache": "11.1.5 || >11.1.6 <12", "find-up": "^5.0.0", "glob-parent": "^6.0.2", "ignore": "^5.2.0", @@ -2608,12 +2749,12 @@ "dev": true }, "file-entry-cache": { - "version": "8.0.0", - "resolved": "https://registry.npmjs.org/file-entry-cache/-/file-entry-cache-8.0.0.tgz", - "integrity": "sha512-XXTUwCvisa5oacNGRP9SfNtYBNAMi+RPwBFmblZEF7N7swHYQS6/Zfk7SRwx4D5j3CH211YNRco1DEMNVfZCnQ==", + "version": "11.1.5", + "resolved": "https://registry.npmjs.org/file-entry-cache/-/file-entry-cache-11.1.5.tgz", + "integrity": "sha512-+PFTHITI08JIGhnNpGNI8T8inUpgZfk3GNEqfT9R2zZV2iFXg3CvqzSl/uEhs7TSGujYRELEANyDvS8Fj7+S7Q==", "dev": true, "requires": { - "flat-cache": "^4.0.0" + "flat-cache": "^6.1.23" } }, "finalhandler": { @@ -2640,19 +2781,20 @@ } }, "flat-cache": { - "version": "4.0.1", - "resolved": "https://registry.npmjs.org/flat-cache/-/flat-cache-4.0.1.tgz", - "integrity": "sha512-f7ccFPK3SXFHpx15UIGyRJ/FJQctuKZ0zVuN3frBo4HnK3cay9VEW0R6yPYFHC0AgqhukPzKjq22t5DmAyqGyw==", + "version": "6.1.23", + "resolved": "https://registry.npmjs.org/flat-cache/-/flat-cache-6.1.23.tgz", + "integrity": "sha512-f++BY9pTk+983xK1FLzlLpmM0i0z+jHmx3QESGkURMXujQZz1k5wzwX6hjnQ8goaD0B+sYnDK1yZ6MTyZfUaqA==", "dev": true, "requires": { - "flatted": "^3.2.9", - "keyv": "^4.5.4" + "cacheable": "^2.5.0", + "flatted": "^3.4.2", + "hookified": "^1.15.0" } }, "flatted": { - "version": "3.4.2", - "resolved": "https://registry.npmjs.org/flatted/-/flatted-3.4.2.tgz", - "integrity": "sha512-PjDse7RzhcPkIJwy5t7KPWQSZ9cAbzQXcafsetQoD7sOJRQlGikNbx7yZp2OotDnJyrDcbyRq3Ttb18iYOqkxA==", + "version": "3.4.4", + "resolved": "https://registry.npmjs.org/flatted/-/flatted-3.4.4.tgz", + "integrity": "sha512-5+ybhBZANEJxaH3X5evAFatUxLfEHSr7n6kYJ+1Qd0mUqr4eu9gIf6GDbWHf8RJijHrjjO8G+la14SlL2SeS1Q==", "dev": true }, "form-data": { @@ -2738,9 +2880,9 @@ } }, "globals": { - "version": "17.11.0", - "resolved": "https://registry.npmjs.org/globals/-/globals-17.11.0.tgz", - "integrity": "sha512-Z2I8hM+PbJDXQDq3Icgpzv+mPdwr68iZUU9d5WW4FuXfDUQfkZaZuvjMv42/5crNyw154+9+VWXbYrUgDXbxNw==", + "version": "17.12.0", + "resolved": "https://registry.npmjs.org/globals/-/globals-17.12.0.tgz", + "integrity": "sha512-cezEd/DTyyht9cvSSURyygXPfy04GtWO/5e6ZPvH7fCtjKz9PYOmuawphw1Ctd1f6C+5JypXfGD7ahNMXvevBA==", "dev": true }, "gopd": { @@ -2762,6 +2904,15 @@ "has-symbols": "^1.0.3" } }, + "hashery": { + "version": "1.5.1", + "resolved": "https://registry.npmjs.org/hashery/-/hashery-1.5.1.tgz", + "integrity": "sha512-iZyKG96/JwPz1N55vj2Ie2vXbhu440zfUfJvSwEqEbeLluk7NnapfGqa7LH0mOsnDxTF85Mx8/dyR6HfqcbmbQ==", + "dev": true, + "requires": { + "hookified": "^1.15.0" + } + }, "hasown": { "version": "2.0.4", "resolved": "https://registry.npmjs.org/hasown/-/hasown-2.0.4.tgz", @@ -2770,6 +2921,12 @@ "function-bind": "^1.1.2" } }, + "hookified": { + "version": "1.15.1", + "resolved": "https://registry.npmjs.org/hookified/-/hookified-1.15.1.tgz", + "integrity": "sha512-MvG/clsADq1GPM2KGo2nyfaWVyn9naPiXrqIe4jYjXNZQt238kWyOGrsyc/DmRAQ+Re6yeo6yX/yoNCG5KAEVg==", + "dev": true + }, "http-errors": { "version": "2.0.1", "resolved": "https://registry.npmjs.org/http-errors/-/http-errors-2.0.1.tgz", @@ -2838,12 +2995,6 @@ "integrity": "sha512-RHxMLp9lnKHGHRng9QFhRCMbYAcVpn69smSGcq3f36xjgVVWThj4qqLbTLlq7Ssj8B+fIQ1EuCEGI2lKsyQeIw==", "dev": true }, - "json-buffer": { - "version": "3.0.1", - "resolved": "https://registry.npmjs.org/json-buffer/-/json-buffer-3.0.1.tgz", - "integrity": "sha512-4bV5BfR2mqfQTJm+V5tPPdf+ZpuhiIvTuAB5g8kcrXOZpTT/QwwVRWBywX1ozr6lEuPdbHxwaJlm9G6mI2sfSQ==", - "dev": true - }, "json-schema-traverse": { "version": "0.4.1", "resolved": "https://registry.npmjs.org/json-schema-traverse/-/json-schema-traverse-0.4.1.tgz", @@ -2857,12 +3008,12 @@ "dev": true }, "keyv": { - "version": "4.5.4", - "resolved": "https://registry.npmjs.org/keyv/-/keyv-4.5.4.tgz", - "integrity": "sha512-oxVHkHR/EJf2CNXnWxRLW6mg7JyCCUcG0DtEGmL2ctUo1PNTin1PUil+r/+4r5MpVgC/fn1kjsx7mjSujKqIpw==", + "version": "5.6.0", + "resolved": "https://registry.npmjs.org/keyv/-/keyv-5.6.0.tgz", + "integrity": "sha512-CYDD3SOtsHtyXeEORYRx2qBtpDJFjRTGXUtmNEMGyzYOKj1TE3tycdlho7kA1Ufx9OYWZzg52QFBGALTirzDSw==", "dev": true, "requires": { - "json-buffer": "3.0.1" + "@keyv/serialize": "^1.1.1" } }, "levn": { @@ -3036,6 +3187,23 @@ "integrity": "sha512-vYt7UD1U9Wg6138shLtLOvdAu+8DsC/ilFtEVHcH+wydcSpNE20AfSOduf6MkRFahL5FY7X1oU7nKVZFtfq8Fg==", "dev": true }, + "qified": { + "version": "0.10.1", + "resolved": "https://registry.npmjs.org/qified/-/qified-0.10.1.tgz", + "integrity": "sha512-+Owyggi9IxT1ePKGafcI87ubSmxol6smwJ+RAHDQlx9+9cPwFWDiKFFCPuWhr9ignlGpZ9vDQLw67N4dcTVFEA==", + "dev": true, + "requires": { + "hookified": "^2.1.1" + }, + "dependencies": { + "hookified": { + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/hookified/-/hookified-2.2.0.tgz", + "integrity": "sha512-p/LgFzRN5FeoD3DLS6bkUapeye6E4SI6yJs6KetENd18S+FBthqYq2amJUWpt5z0EQwwHemidjY5OqJGEKm5uA==", + "dev": true + } + } + }, "qs": { "version": "6.16.0", "resolved": "https://registry.npmjs.org/qs/-/qs-6.16.0.tgz", diff --git a/package.json b/package.json index 165cca9..84bcd6e 100644 --- a/package.json +++ b/package.json @@ -25,8 +25,8 @@ "license": "MIT", "devDependencies": { "@eslint/js": "^10.0.1", - "eslint": "^10.9.1", - "globals": "^17.11.0", + "eslint": "^10.10.0", + "globals": "^17.12.0", "supertest": "^7.2.2" } } From a8d536aeaf052dcbd0ba6f756fd22af68bcb2350 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 18 Sep 2026 05:44:23 +0000 Subject: [PATCH 46/57] Bump docker/build-push-action from 7.3.0 to 7.4.0 (#287) Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 7.3.0 to 7.4.0. - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc) --- updated-dependencies: - dependency-name: docker/build-push-action dependency-version: 7.4.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/ci.yaml | 4 ++-- .github/workflows/publish.yaml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 4de9a96..0b6c85d 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -59,7 +59,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - name: Build test target - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 + uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: test @@ -67,7 +67,7 @@ jobs: cache-from: type=gha,scope=test cache-to: type=gha,mode=max,scope=test - name: Build production target - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 + uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . target: production diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 9dbda74..2cf217d 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -48,7 +48,7 @@ jobs: type=raw,value=latest,enable=${{ (github.event_name == 'workflow_dispatch' && github.ref_name == 'master') || github.event.workflow_run.head_branch == 'master' }} type=raw,value=${{ steps.package.outputs.version }},enable=${{ (github.event_name == 'workflow_dispatch' && github.ref_name == 'master') || github.event.workflow_run.head_branch == 'master' }} - name: Build and push - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7 + uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7 with: context: . target: production From b59178ae838947060135ccdf1401f7be20824fa8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 18 Sep 2026 05:47:00 +0000 Subject: [PATCH 47/57] Bump docker/setup-qemu-action from 4.3.0 to 4.4.0 (#288) Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 4.3.0 to 4.4.0. - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](https://github.com/docker/setup-qemu-action/compare/1f40c72289eff860ee54a304f1438e3cff362e0a...99012661954931238ded8c8b007157a8430204e1) --- updated-dependencies: - dependency-name: docker/setup-qemu-action dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/publish.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 2cf217d..a8afbe1 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -26,7 +26,7 @@ jobs: with: ref: ${{ github.event_name == 'workflow_dispatch' && github.sha || github.event.workflow_run.head_sha }} - name: Set up QEMU - uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4 + uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4 - name: Log in to Docker Hub From 894dbf50495988edb13a7cca0342436ee86636ca Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 18 Sep 2026 05:49:16 +0000 Subject: [PATCH 48/57] Bump docker/setup-buildx-action from 4.3.0 to 4.4.0 (#290) Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.3.0 to 4.4.0. - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/37fe631027851001ddb9b187196cc803df7f5f0e...594f3bf4285d9ea8dc53c9a0c9c4092420091003) --- updated-dependencies: - dependency-name: docker/setup-buildx-action dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/ci.yaml | 2 +- .github/workflows/publish.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 0b6c85d..b438fb0 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -57,7 +57,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + - uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4.4.0 - name: Build test target uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index a8afbe1..1b10ae5 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -28,7 +28,7 @@ jobs: - name: Set up QEMU uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4 + uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4 - name: Log in to Docker Hub uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 with: From ddbb934c82b84439b145864799afcb53a6d69ffa Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 18 Sep 2026 05:52:44 +0000 Subject: [PATCH 49/57] Bump github/codeql-action/analyze from 4.37.9 to 4.38.0 (#291) Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.9 to 4.38.0. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index f72fcd9..babf349 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -21,4 +21,4 @@ jobs: - uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: languages: javascript-typescript - - uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 From a2495e1ac5debcac65048a7d62eef5ad3dcf93c5 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 18 Sep 2026 05:56:01 +0000 Subject: [PATCH 50/57] Bump github/codeql-action/init from 4.37.9 to 4.38.0 (#289) Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.9 to 4.38.0. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index babf349..99757d9 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: languages: javascript-typescript - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 From 6ae5e4535e6feaddb3c46c7d68540e9841a4aa18 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Fri, 18 Sep 2026 23:32:32 -0700 Subject: [PATCH 51/57] Configure npm Minimum Release Age and Patch proxy-addr (#292) * Configure npm Minimum Release Age * Update proxy-addr to 2.0.8 --- .npmrc | 1 + package-lock.json | 12 ++++++------ 2 files changed, 7 insertions(+), 6 deletions(-) create mode 100644 .npmrc diff --git a/.npmrc b/.npmrc new file mode 100644 index 0000000..7253a5c --- /dev/null +++ b/.npmrc @@ -0,0 +1 @@ +min-release-age=7 diff --git a/package-lock.json b/package-lock.json index c7c547e..4ce5357 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1671,9 +1671,9 @@ } }, "node_modules/proxy-addr": { - "version": "2.0.7", - "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.7.tgz", - "integrity": "sha512-llQsMLSUDUPT44jdrU/O37qlnifitDP+ZwrmmZcoSKyLKvtZxpyV0n2/bD/N4tBAAZ/gJEdZU7KMraoK1+XYAg==", + "version": "2.0.8", + "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.8.tgz", + "integrity": "sha512-5nnx0yGyVUcY6t9RnWcARWtwT9F1D8O9rt08htPvnd49W1IgZtmLkhu9WfMzQj1cFxjHIO6connUNVW5k7AVyQ==", "dependencies": { "forwarded": "0.2.0", "ipaddr.js": "1.9.1" @@ -3173,9 +3173,9 @@ "dev": true }, "proxy-addr": { - "version": "2.0.7", - "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.7.tgz", - "integrity": "sha512-llQsMLSUDUPT44jdrU/O37qlnifitDP+ZwrmmZcoSKyLKvtZxpyV0n2/bD/N4tBAAZ/gJEdZU7KMraoK1+XYAg==", + "version": "2.0.8", + "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.8.tgz", + "integrity": "sha512-5nnx0yGyVUcY6t9RnWcARWtwT9F1D8O9rt08htPvnd49W1IgZtmLkhu9WfMzQj1cFxjHIO6connUNVW5k7AVyQ==", "requires": { "forwarded": "0.2.0", "ipaddr.js": "1.9.1" From 01043ba99681cad120dfc211de65b3f7ebb613f6 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 05:46:42 +0000 Subject: [PATCH 52/57] Bump github/codeql-action/analyze from 4.38.0 to 4.38.1 (#293) Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.38.0 to 4.38.1. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 99757d9..b8c750b 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -21,4 +21,4 @@ jobs: - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 with: languages: javascript-typescript - - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 From 1be395e445b0298a62cd609b3b22719bf83fc755 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Sep 2026 15:07:38 -0700 Subject: [PATCH 53/57] Bump github/codeql-action/init from 4.38.0 to 4.38.1 (#294) Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.38.0 to 4.38.1. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index b8c750b..8f5ac55 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: languages: javascript-typescript - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 From 07f986084da7ed46d0ab1da7f72aecaa074aa819 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Tue, 29 Sep 2026 22:30:29 -0700 Subject: [PATCH 54/57] Fix Dependabot publication dispatch (#295) --- .github/workflows/dependabot-auto-merge.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index b03c8ac..75b15fc 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -47,6 +47,6 @@ jobs: runs-on: ubuntu-latest steps: - name: Dispatch publication from the merged master revision - run: gh workflow run publish.yaml --ref master + run: gh workflow run publish.yaml --repo "$GITHUB_REPOSITORY" --ref master env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} From a6f93cfba40c079b2df1106fe1c87ab503587248 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 30 Sep 2026 05:32:58 +0000 Subject: [PATCH 55/57] Bump brace-expansion from 5.0.9 to 5.0.12 (#296) Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.9 to 5.0.12. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](https://github.com/juliangruber/brace-expansion/compare/v5.0.9...v5.0.12) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.12 dependency-type: indirect ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/package-lock.json b/package-lock.json index 4ce5357..db9617c 100644 --- a/package-lock.json +++ b/package-lock.json @@ -440,9 +440,9 @@ } }, "node_modules/brace-expansion": { - "version": "5.0.9", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz", - "integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==", + "version": "5.0.12", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.12.tgz", + "integrity": "sha512-YovQ3rzhaLMIrDjNDMkNS01tea93qhEhG5xy8f6+R0l+dw3Ki+5sCoIoI942iuLZTHWogWktgwVDhU09iNEimQ==", "dev": true, "license": "MIT", "dependencies": { @@ -2365,9 +2365,9 @@ } }, "brace-expansion": { - "version": "5.0.9", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz", - "integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==", + "version": "5.0.12", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.12.tgz", + "integrity": "sha512-YovQ3rzhaLMIrDjNDMkNS01tea93qhEhG5xy8f6+R0l+dw3Ki+5sCoIoI942iuLZTHWogWktgwVDhU09iNEimQ==", "dev": true, "requires": { "balanced-match": "^4.0.2" From 7fe5d9d1cbbe6c9007facaa9914cba8d5a339c1c Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Tue, 29 Sep 2026 22:56:20 -0700 Subject: [PATCH 56/57] Enforce Production Security and Release Gates --- .github/dependabot.yml | 3 + .github/workflows/ci.yaml | 1 + .github/workflows/codeql.yml | 1 + .github/workflows/dependabot-auto-merge.yml | 31 ++----- .github/workflows/publish.yaml | 93 ++++++++++++++++++--- .github/workflows/snyk.yml | 20 ++--- 6 files changed, 100 insertions(+), 49 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index ea3a0c0..5a5c3de 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -2,6 +2,7 @@ version: 2 updates: - package-ecosystem: npm directory: / + target-branch: develop schedule: interval: weekly groups: @@ -9,9 +10,11 @@ updates: patterns: ["*"] - package-ecosystem: github-actions directory: / + target-branch: develop schedule: interval: weekly - package-ecosystem: docker directory: / + target-branch: develop schedule: interval: weekly diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index b438fb0..1ceb589 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -1,6 +1,7 @@ name: CI on: + workflow_dispatch: push: branches: [develop, master] pull_request: diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 8f5ac55..eff8fbe 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,6 +1,7 @@ name: CodeQL on: + workflow_dispatch: push: branches: [develop, master] pull_request: diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index 75b15fc..cdeddab 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -2,7 +2,7 @@ name: Dependabot Auto Merge on: pull_request_target: - types: [opened, synchronize, reopened, ready_for_review, closed] + types: [opened, synchronize, reopened, ready_for_review] permissions: contents: write @@ -10,43 +10,26 @@ permissions: jobs: enable-automerge: - if: > - github.event.action != 'closed' && + if: >- + github.event.pull_request.base.ref == 'develop' && github.event.pull_request.user.login == 'dependabot[bot]' && startsWith(github.event.pull_request.head.ref, 'dependabot/') && github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.draft == false runs-on: ubuntu-latest + timeout-minutes: 5 steps: - - name: Fetch Dependabot metadata + - name: Fetch Dependabot Metadata id: metadata uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} - - name: Enable auto-merge - if: > + - name: Enable Auto-Merge + if: >- steps.metadata.outputs.update-type == 'version-update:semver-patch' || steps.metadata.outputs.update-type == 'version-update:semver-minor' run: gh pr merge --auto --squash "$PR_URL" env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} PR_URL: ${{ github.event.pull_request.html_url }} - - publish-after-merged-dependabot: - if: > - github.event.action == 'closed' && - github.event.pull_request.merged == true && - github.event.pull_request.base.ref == 'master' && - github.event.pull_request.user.login == 'dependabot[bot]' && - startsWith(github.event.pull_request.head.ref, 'dependabot/') && - github.event.pull_request.head.repo.full_name == github.repository - permissions: - actions: write - contents: read - runs-on: ubuntu-latest - steps: - - name: Dispatch publication from the merged master revision - run: gh workflow run publish.yaml --repo "$GITHUB_REPOSITORY" --ref master - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 1b10ae5..d82e3e4 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -11,20 +11,90 @@ permissions: contents: read concurrency: - group: publish-${{ github.event.workflow_run.head_branch }} + group: publish-${{ github.event_name == 'workflow_dispatch' && github.ref_name || github.event.workflow_run.head_branch }} cancel-in-progress: false jobs: - container: - name: Publish container - if: > + verify: + name: Verify Release Checks + if: >- github.event_name == 'workflow_dispatch' || (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push') runs-on: ubuntu-latest + timeout-minutes: 15 + permissions: + actions: write + checks: read + contents: read + outputs: + sha: ${{ steps.release.outputs.sha }} + branch: ${{ steps.release.outputs.branch }} + steps: + - name: Verify Exact Release Commit + id: release + env: + GH_TOKEN: ${{ github.token }} + GH_REPO: ${{ github.repository }} + RELEASE_SHA: ${{ github.event_name == 'workflow_dispatch' && github.sha || github.event.workflow_run.head_sha }} + RELEASE_BRANCH: ${{ github.event_name == 'workflow_dispatch' && github.ref_name || github.event.workflow_run.head_branch }} + MANUAL_RELEASE: ${{ github.event_name == 'workflow_dispatch' }} + run: | + case "$RELEASE_BRANCH" in + develop|master) ;; + *) echo "Unsupported release branch: $RELEASE_BRANCH" >&2; exit 1 ;; + esac + current_sha="$(gh api "repos/$GH_REPO/commits/$RELEASE_BRANCH" --jq .sha)" + if [ "$current_sha" != "$RELEASE_SHA" ]; then + echo "Release commit is no longer the branch head." >&2 + exit 1 + fi + + # Manual releases rerun all checks, including the current vulnerability data. + check_after="$(date -u -d '24 hours ago' +%Y-%m-%dT%H:%M:%SZ)" + if [ "$MANUAL_RELEASE" = true ]; then + check_after="$(date -u +%Y-%m-%dT%H:%M:%SZ)" + for workflow in ci.yaml snyk.yml codeql.yml; do + gh workflow run "$workflow" --ref "$RELEASE_BRANCH" + done + fi + + if [ "$RELEASE_BRANCH" = master ]; then + required='["Test (Node 26)","Lint and audit","Helm lint and render","Build container","Open Source and Container","Analyze JavaScript"]' + else + required='["Test (Node 22)","Test (Node 24)","Lint and audit","Helm lint and render","Build container","Open Source","Analyze JavaScript"]' + fi + + for attempt in {1..60}; do + checks="$(gh api --paginate --slurp "repos/$GH_REPO/commits/$RELEASE_SHA/check-runs?per_page=100")" + missing="$(jq -r --argjson required "$required" --arg after "$check_after" ' + [.[].check_runs[] | select(.app.slug == "github-actions")] as $runs + | $required[] as $name + | ([$runs[] | select(.name == $name)] | max_by(.id)) as $latest + | select($latest == null or $latest.status != "completed" + or $latest.conclusion != "success" or $latest.started_at < $after) + | $name + ' <<< "$checks")" + if [ -z "$missing" ]; then + current_sha="$(gh api "repos/$GH_REPO/commits/$RELEASE_BRANCH" --jq .sha)" + test "$current_sha" = "$RELEASE_SHA" + echo "sha=$RELEASE_SHA" >> "$GITHUB_OUTPUT" + echo "branch=$RELEASE_BRANCH" >> "$GITHUB_OUTPUT" + exit 0 + fi + echo "Waiting for successful checks on $RELEASE_SHA: $missing" + sleep 10 + done + echo "Release blocked by missing, stale, skipped, or failed checks: $missing" >&2 + exit 1 + + container: + name: Publish container + needs: verify + runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - ref: ${{ github.event_name == 'workflow_dispatch' && github.sha || github.event.workflow_run.head_sha }} + ref: ${{ needs.verify.outputs.sha }} - name: Set up QEMU uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4 - name: Set up Docker Buildx @@ -44,9 +114,9 @@ jobs: images: jonfairbanks/docker-node-app tags: | type=sha - type=raw,value=develop,enable=${{ (github.event_name == 'workflow_dispatch' && github.ref_name == 'develop') || github.event.workflow_run.head_branch == 'develop' }} - type=raw,value=latest,enable=${{ (github.event_name == 'workflow_dispatch' && github.ref_name == 'master') || github.event.workflow_run.head_branch == 'master' }} - type=raw,value=${{ steps.package.outputs.version }},enable=${{ (github.event_name == 'workflow_dispatch' && github.ref_name == 'master') || github.event.workflow_run.head_branch == 'master' }} + type=raw,value=develop,enable=${{ needs.verify.outputs.branch == 'develop' }} + type=raw,value=latest,enable=${{ needs.verify.outputs.branch == 'master' }} + type=raw,value=${{ steps.package.outputs.version }},enable=${{ needs.verify.outputs.branch == 'master' }} - name: Build and push uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7 with: @@ -61,9 +131,8 @@ jobs: helm: name: Publish Helm chart - if: > - (github.event_name == 'workflow_dispatch' && github.ref_name == 'master') || - (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'push' && github.event.workflow_run.head_branch == 'master') + needs: verify + if: needs.verify.outputs.branch == 'master' runs-on: ubuntu-latest permissions: contents: read @@ -71,7 +140,7 @@ jobs: steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - ref: ${{ github.event_name == 'workflow_dispatch' && github.sha || github.event.workflow_run.head_sha }} + ref: ${{ needs.verify.outputs.sha }} fetch-depth: 2 - name: Set up Helm uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index a5f19a5..8bc65bc 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -19,36 +19,32 @@ permissions: jobs: open-source: name: Open Source and Container - if: >- - github.actor != 'dependabot[bot]' && - (github.event_name != 'pull_request' || - github.event.pull_request.head.repo.full_name == github.repository) runs-on: ubuntu-latest + timeout-minutes: 15 env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} steps: - - name: Check Snyk configuration - if: env.SNYK_TOKEN == '' - run: echo "::warning::SNYK_TOKEN is not configured; skipping Snyk scan." + - name: Require Snyk Token + run: | + if [ -z "$SNYK_TOKEN" ]; then + echo "::error::SNYK_TOKEN is required. Configure it in Actions and Dependabot secrets." + exit 1 + fi - name: Checkout - if: env.SNYK_TOKEN != '' uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Use Node.js 24.x - if: env.SNYK_TOKEN != '' uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 24.x cache: npm - name: Install dependencies - if: env.SNYK_TOKEN != '' run: npm ci - name: Scan dependencies - if: env.SNYK_TOKEN != '' uses: snyk/actions/node@9adf32b1121593767fc3c057af55b55db032dc04 # v1.0.0 with: args: >- @@ -57,11 +53,9 @@ jobs: --severity-threshold=high - name: Build production image - if: env.SNYK_TOKEN != '' run: docker build --target production --tag docker-node-app:snyk . - name: Scan production image - if: env.SNYK_TOKEN != '' run: | # snyk/actions/docker invokes the legacy `snyk test --docker` path. # Use Snyk's current container command with the current immutable From 2c110059293de23b30610170557a0f0f8182fab4 Mon Sep 17 00:00:00 2001 From: Jon Fairbanks Date: Tue, 29 Sep 2026 22:58:54 -0700 Subject: [PATCH 57/57] Explain Release Blocking When the Branch Advances --- .github/workflows/publish.yaml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index d82e3e4..caae37c 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -76,7 +76,10 @@ jobs: ' <<< "$checks")" if [ -z "$missing" ]; then current_sha="$(gh api "repos/$GH_REPO/commits/$RELEASE_BRANCH" --jq .sha)" - test "$current_sha" = "$RELEASE_SHA" + if [ "$current_sha" != "$RELEASE_SHA" ]; then + echo "Branch advanced while checks were running; release blocked." >&2 + exit 1 + fi echo "sha=$RELEASE_SHA" >> "$GITHUB_OUTPUT" echo "branch=$RELEASE_BRANCH" >> "$GITHUB_OUTPUT" exit 0