Skip to content

chore: upgrade fast-uri to ^3.1.8 to address CVE-2026-86472 #30

chore: upgrade fast-uri to ^3.1.8 to address CVE-2026-86472

chore: upgrade fast-uri to ^3.1.8 to address CVE-2026-86472 #30

name: Setup wizard verification
on:
pull_request:
paths:
- 'packages/setupWizard/**'
- 'packages/schemas/**'
- 'entrypoint.sh'
- 'yarn.lock'
- '.github/workflows/setup-wizard-e2e.yml'
- '.github/workflows/release-setup-sourcebot.yml'
workflow_dispatch:
permissions:
contents: read
jobs:
platform:
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
node: ['20.20.0', '22.22.0', '24.x']
runs-on: ${{ matrix.os }}
env:
PACKAGE_TRACKER_ANALYTICS: 'false'
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: actions/setup-node@v4
with:
node-version: '24.x'
- run: corepack enable
- run: yarn install --immutable --mode=skip-build
- run: yarn rebuild node-pty
- run: yarn workspace @sourcebot/schemas build
- run: yarn workspace setup-sourcebot build
- name: Pack on the release runtime
shell: bash
env:
SETUP_TEST_TARBALL: ${{ runner.temp }}/setup-sourcebot.tgz
run: |
yarn workspace setup-sourcebot pack --out "$SETUP_TEST_TARBALL"
echo "SETUP_TEST_TARBALL=$SETUP_TEST_TARBALL" >> "$GITHUB_ENV"
- name: Select end-user test runtime
uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node }}
- run: corepack enable
- run: yarn workspace setup-sourcebot test
- run: yarn workspace setup-sourcebot test:platform
- name: Linux minimum-runtime regression checks
if: runner.os == 'Linux' && matrix.node != '24.x'
working-directory: packages/setupWizard
run: node --test --test-concurrency=1 tests/e2e/wizard.test.mjs tests/e2e/collectors.test.mjs tests/e2e/docker.test.mjs tests/e2e/safety.test.mjs
- name: Linux packed-artifact and runtime checks
if: runner.os == 'Linux' && matrix.node == '24.x'
run: |
docker pull docker.sourcebot.dev/sourcebot-dev/sourcebot:latest
yarn workspace setup-sourcebot test:e2e
yarn workspace setup-sourcebot test:baseline
node packages/setupWizard/tests/e2e/packageManagers.mjs
setup-wizard-e2e:
if: always()
needs: [platform]
runs-on: ubuntu-latest
steps:
- name: Require every platform job
env:
RESULT: ${{ needs.platform.result }}
run: test "$RESULT" = success