Repository navigation
🚀 release: promote build flow and toolchain updates - #92
warengonzaga wants to merge 6 commits into
Conversation
…90) Bumps [wgtechlabs/build-flow-action/.github/workflows/app.yml](https://github.com/wgtechlabs/build-flow-action) from 0.2.0 to 0.2.1. - [Release notes](https://github.com/wgtechlabs/build-flow-action/releases) - [Changelog](https://github.com/wgtechlabs/build-flow-action/blob/main/CHANGELOG.md) - [Commits](wgtechlabs/build-flow-action@v0.2.0...v0.2.1) --- updated-dependencies: - dependency-name: wgtechlabs/build-flow-action/.github/workflows/app.yml dependency-version: 0.2.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](microsoft/TypeScript@v6.0.3...v7.0.2) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.5 to 26.4.0. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.4.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minor-and-patch group with 1 update: [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome). Updates `@biomejs/biome` from 2.4.16 to 2.5.11 - [Release notes](https://github.com/biomejs/biome/releases) - [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md) - [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.11/packages/@biomejs/biome) --- updated-dependencies: - dependency-name: "@biomejs/biome" dependency-version: 2.5.11 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* ☕ chore: bump wgtechlabs/build-flow-action/.github/workflows/app.yml Bumps [wgtechlabs/build-flow-action/.github/workflows/app.yml](https://github.com/wgtechlabs/build-flow-action) from 0.2.1 to 0.3.1. - [Release notes](https://github.com/wgtechlabs/build-flow-action/releases) - [Changelog](https://github.com/wgtechlabs/build-flow-action/blob/main/CHANGELOG.md) - [Commits](wgtechlabs/build-flow-action@v0.2.1...v0.3.1) --- updated-dependencies: - dependency-name: wgtechlabs/build-flow-action/.github/workflows/app.yml dependency-version: 0.3.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> * ☕ chore: sync toolchain lockfile and biome configuration --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Waren Gonzaga <opensource@warengonzaga.com>
🛠️ Container Build Complete - Dev BuildBuild Status: ✅ Success 📦 Pull ImageDocker Hub: docker pull wgtechlabs/unthread-webhook-server:dev-ca4970dGHCR: docker pull ghcr.io/wgtechlabs/unthread-webhook-server:dev-ca4970d📋 Build Details
🏷️ Image Tags• 🔍 Testing Your Changes
🚀 Quick Start# Pull and run the container
Docker Hub: docker pull wgtechlabs/unthread-webhook-server:dev-ca4970d
docker run <your-options> <image>🔒 Security Scan Results📋 Pre-Build Security Checks✅ Source Code Scan: 1 vulnerabilities found 🐳 Container Image Vulnerabilities
📋 View Vulnerability DetailsNode.js
📊 Detailed Security ReportsView detailed vulnerability reports in the GitHub Security tab. 🤖 Powered by Container Build Flow Action vfb5c0662b33f7702bc1ccf85350689436989f606 |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
TypeScript 7 breaks the existing ts-node development startup command.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Promotes build automation and development toolchain updates from dev to main, without changing application runtime dependencies.
Changes:
- Updates Build Flow to v0.3.1.
- Upgrades TypeScript, Node.js types, and Biome, with synchronized lockfile entries.
- Migrates Biome configuration while preserving rule severities.
| File | Description |
|---|---|
| package.json | Updates development toolchain versions. |
| bun.lock | Synchronizes dependencies and platform packages. |
| biome.json | Migrates schema, preset, and rule locations. |
| .github/workflows/build-flow.yml | Uses Build Flow v0.3.1. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Pin the reusable workflow to its release commit and replace incompatible ts-node startup with watched compilation followed by Node execution.
warengonzaga
left a comment
There was a problem hiding this comment.
Clean Workflow postintegration review: no remaining actionable findings in the promotion diff at 13b50f6e8113ca27fce00bdccfb1098f5da0dda6 against main d7970cd33c6d07598067dcd5a98c7afc63605701.
Merged repair #93 fixes the annotated-tag workflow resolution failure and the TypeScript 7/ts-node startup regression. The integrated tree exactly matches the reviewed and smoke-tested repair. The current five-file promotion diff preserves application source and runtime dependency versions; the Biome migration preserves rule severity. A synthetic merge with current main is conflict-free and preserves main's release metadata.
The dev push and promotion run both passed. Each resolved app.yml, ci.yml, and codeql.yml at the verified Build Flow release commit 260b9a063ef59ccc760155c19902320feb7e25cb. Node 22/24/26 checks, CodeQL execution, container flow, Snyk, Trivy, and current Code Quality analysis completed successfully. No checks or requested reviews remain pending. Copilot's original finding is addressed by #93; the repair's completed Copilot review found no additional issues.
Local frozen install, lint, typecheck, build, and 35 tests passed on the identical source tree. The development smoke test verified startup progression, compilation-error rejection without stale startup, and automatic recovery after correction. Limits remain: no healthy Redis-backed local startup; a neutral CodeQL comparison result due to the legacy main-branch container.yml configuration; and the existing critical proxy-addr CVE-2026-90711 reported by the container scan. These warnings are not new runtime dependency changes in this promotion.
Ready for a promotion decision with those disclosed limits. No promotion approval or merge was performed.

Promotes
devtomainwith Build Flow v0.3.1, TypeScript 7.0.2, Node.js type definitions 26.4.0, and Biome 2.5.11. Includes #87, #88, #89, #90, and #91, with the synchronized Bun lockfile and equivalent Biome configuration migration.Supporting repair #93 is merged at
13b50f6e8113ca27fce00bdccfb1098f5da0dda6. It pins Build Flow to the verified v0.3.1 release commit and replaces the incompatible ts-node development runner with watched compilation followed by Node startup. Failed compilation blocks stale startup and keeps the watcher alive for recovery. Application source and runtime dependency versions are unchanged.Readiness: conflict-free and ready for a promotion decision at head
13b50f6e8113ca27fce00bdccfb1098f5da0dda6against maind7970cd33c6d07598067dcd5a98c7afc63605701. The dev push and promotion run passed, including validation on Node 22/24/26, CodeQL execution, and container flow. Snyk, Trivy, and the current Code Quality run passed. The original development-runner finding is addressed in #93 and verified on this head.Local frozen install, lint, typecheck, build, and all 35 tests passed on the identical repaired source tree. A bounded smoke test verified initial compiled startup, blocked startup on a type error, and automatic rebuild/restart after correction. A healthy Redis-backed startup was not exercised. CodeQL's separate comparison result remains neutral because the legacy
container.ymlconfiguration on main is absent from the current analysis. The container report flags the existing critical proxy-addr vulnerability (CVE-2026-90711), whose runtime dependency record is unchanged by this promotion.Use Create a merge commit when the promotion is approved so release automation can inspect the individual commits. This PR has not been merged.