Skip to content

🚀 release: promote build flow and toolchain updates - #92

Open
warengonzaga wants to merge 6 commits into
mainfrom
dev
Open

warengonzaga wants to merge 6 commits into
mainfrom
dev

Conversation

@warengonzaga

@warengonzaga warengonzaga commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Promotes dev to main with Build Flow v0.3.1, TypeScript 7.0.2, Node.js type definitions 26.4.0, and Biome 2.5.11. Includes #87, #88, #89, #90, and #91, with the synchronized Bun lockfile and equivalent Biome configuration migration.

Supporting repair #93 is merged at 13b50f6e8113ca27fce00bdccfb1098f5da0dda6. It pins Build Flow to the verified v0.3.1 release commit and replaces the incompatible ts-node development runner with watched compilation followed by Node startup. Failed compilation blocks stale startup and keeps the watcher alive for recovery. Application source and runtime dependency versions are unchanged.

Readiness: conflict-free and ready for a promotion decision at head 13b50f6e8113ca27fce00bdccfb1098f5da0dda6 against main d7970cd33c6d07598067dcd5a98c7afc63605701. The dev push and promotion run passed, including validation on Node 22/24/26, CodeQL execution, and container flow. Snyk, Trivy, and the current Code Quality run passed. The original development-runner finding is addressed in #93 and verified on this head.

Local frozen install, lint, typecheck, build, and all 35 tests passed on the identical repaired source tree. A bounded smoke test verified initial compiled startup, blocked startup on a type error, and automatic rebuild/restart after correction. A healthy Redis-backed startup was not exercised. CodeQL's separate comparison result remains neutral because the legacy container.yml configuration on main is absent from the current analysis. The container report flags the existing critical proxy-addr vulnerability (CVE-2026-90711), whose runtime dependency record is unchanged by this promotion.

Use Create a merge commit when the promotion is approved so release automation can inspect the individual commits. This PR has not been merged.

dependabot Bot and others added 5 commits October 3, 2026 18:12
…90)

Bumps [wgtechlabs/build-flow-action/.github/workflows/app.yml](https://github.com/wgtechlabs/build-flow-action) from 0.2.0 to 0.2.1.
- [Release notes](https://github.com/wgtechlabs/build-flow-action/releases)
- [Changelog](https://github.com/wgtechlabs/build-flow-action/blob/main/CHANGELOG.md)
- [Commits](wgtechlabs/build-flow-action@v0.2.0...v0.2.1)

---
updated-dependencies:
- dependency-name: wgtechlabs/build-flow-action/.github/workflows/app.yml
  dependency-version: 0.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v6.0.3...v7.0.2)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.5 to 26.4.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.4.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minor-and-patch group with 1 update: [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome).


Updates `@biomejs/biome` from 2.4.16 to 2.5.11
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.11/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.11
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* ☕ chore: bump wgtechlabs/build-flow-action/.github/workflows/app.yml

Bumps [wgtechlabs/build-flow-action/.github/workflows/app.yml](https://github.com/wgtechlabs/build-flow-action) from 0.2.1 to 0.3.1.
- [Release notes](https://github.com/wgtechlabs/build-flow-action/releases)
- [Changelog](https://github.com/wgtechlabs/build-flow-action/blob/main/CHANGELOG.md)
- [Commits](wgtechlabs/build-flow-action@v0.2.1...v0.3.1)

---
updated-dependencies:
- dependency-name: wgtechlabs/build-flow-action/.github/workflows/app.yml
  dependency-version: 0.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* ☕ chore: sync toolchain lockfile and biome configuration

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Waren Gonzaga <opensource@warengonzaga.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 04:36
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

🛠️ Container Build Complete - Dev Build

Build Status: ✅ Success
Flow Type: dev
Description: Development and testing


📦 Pull Image

Docker Hub: docker pull wgtechlabs/unthread-webhook-server:dev-ca4970d
GHCR: docker pull ghcr.io/wgtechlabs/unthread-webhook-server:dev-ca4970d

📋 Build Details

Property Value
Flow Type dev
Commit 13b50f6
Registry Docker Hub + GHCR

🏷️ Image Tags

• wgtechlabs/unthread-webhook-server:dev-ca4970d
• wgtechlabs/unthread-webhook-server:dev
• ghcr.io/wgtechlabs/unthread-webhook-server:dev-ca4970d
• ghcr.io/wgtechlabs/unthread-webhook-server:dev


🔍 Testing Your Changes

  1. Pull the image using one of the commands above
  2. Run the container with your test configuration
  3. Verify the changes work as expected
  4. Report any issues in this PR

🚀 Quick Start

# Pull and run the container
Docker Hub: docker pull wgtechlabs/unthread-webhook-server:dev-ca4970d
docker run <your-options> <image>


🔒 Security Scan Results

📋 Pre-Build Security Checks

✅ Source Code Scan: 1 vulnerabilities found
✅ Dockerfile Scan: 0 misconfigurations found

🐳 Container Image Vulnerabilities

Severity Count
🔴 Critical 1
Total 1
📋 View Vulnerability Details

Node.js

  • 🔴 CVE-2026-90711 (CRITICAL) - proxy-addr
    • proxy-addr is a Node.js module that determines a request's client addr ...
    • Fixed in: 2.0.8

📊 Detailed Security Reports

View detailed vulnerability reports in the GitHub Security tab.


🤖 Powered by Container Build Flow Action vfb5c0662b33f7702bc1ccf85350689436989f606
💻 with ❤️ by Waren Gonzaga under WG Technology Labs, and Him 🙏

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

TypeScript 7 breaks the existing ts-node development startup command.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Promotes build automation and development toolchain updates from dev to main, without changing application runtime dependencies.

Changes:

  • Updates Build Flow to v0.3.1.
  • Upgrades TypeScript, Node.js types, and Biome, with synchronized lockfile entries.
  • Migrates Biome configuration while preserving rule severities.
File Description
package.json Updates development toolchain versions.
bun.lock Synchronizes dependencies and platform packages.
biome.json Migrates schema, preset, and rule locations.
.github/​workflows/​build-flow.yml Uses Build Flow v0.3.1.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
Pin the reusable workflow to its release commit and replace incompatible ts-node startup with watched compilation followed by Node execution.

@warengonzaga warengonzaga left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clean Workflow postintegration review: no remaining actionable findings in the promotion diff at 13b50f6e8113ca27fce00bdccfb1098f5da0dda6 against main d7970cd33c6d07598067dcd5a98c7afc63605701.

Merged repair #93 fixes the annotated-tag workflow resolution failure and the TypeScript 7/ts-node startup regression. The integrated tree exactly matches the reviewed and smoke-tested repair. The current five-file promotion diff preserves application source and runtime dependency versions; the Biome migration preserves rule severity. A synthetic merge with current main is conflict-free and preserves main's release metadata.

The dev push and promotion run both passed. Each resolved app.yml, ci.yml, and codeql.yml at the verified Build Flow release commit 260b9a063ef59ccc760155c19902320feb7e25cb. Node 22/24/26 checks, CodeQL execution, container flow, Snyk, Trivy, and current Code Quality analysis completed successfully. No checks or requested reviews remain pending. Copilot's original finding is addressed by #93; the repair's completed Copilot review found no additional issues.

Local frozen install, lint, typecheck, build, and 35 tests passed on the identical source tree. The development smoke test verified startup progression, compilation-error rejection without stale startup, and automatic recovery after correction. Limits remain: no healthy Redis-backed local startup; a neutral CodeQL comparison result due to the legacy main-branch container.yml configuration; and the existing critical proxy-addr CVE-2026-90711 reported by the container scan. These warnings are not new runtime dependency changes in this promotion.

Ready for a promotion decision with those disclosed limits. No promotion approval or merge was performed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants