Repository navigation
🔧 update: repair build flow and development startup - #93
Conversation
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
No blocking code issues were identified, but completion of the container and CodeQL checks remains unverified.
Review effort: Balanced
Findings: None
What changed in this PR
Repairs CI workflow resolution and development startup to support promotion #92 without changing application source or runtime dependencies.
Changes:
- Pins Build Flow to the verified v0.3.1 release commit.
- Replaces ts-node startup with watched compilation followed by Node execution.
- Removes obsolete ts-node configuration and dependencies.
| File | Description |
|---|---|
| tsconfig.json | Removes ts-node-specific configuration. |
| package.json | Gates development startup on successful compilation and removes ts-node. |
| bun.lock | Removes ts-node and its unused dependencies. |
| .github/workflows/build-flow.yml | Pins the reusable workflow to its release commit. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🔧 Container Build Complete - PR BuildBuild Status: ✅ Success 📦 Pull ImageDocker Hub: docker pull wgtechlabs/unthread-webhook-server:pr-3f983b1GHCR: docker pull ghcr.io/wgtechlabs/unthread-webhook-server:pr-3f983b1📋 Build Details
🏷️ Image Tags• 🔍 Testing Your Changes
🚀 Quick Start# Pull and run the container
Docker Hub: docker pull wgtechlabs/unthread-webhook-server:pr-3f983b1
docker run <your-options> <image>🔒 Security Scan Results📋 Pre-Build Security Checks✅ Source Code Scan: 1 vulnerabilities found 🐳 Container Image Vulnerabilities
📋 View Vulnerability DetailsNode.js
📊 Detailed Security ReportsView detailed vulnerability reports in the GitHub Security tab. 🤖 Powered by Container Build Flow Action vfb5c0662b33f7702bc1ccf85350689436989f606 |
warengonzaga
left a comment
There was a problem hiding this comment.
Clean Workflow final review: no actionable findings in the four-file repair diff at 1e49f92d8aefd6049f5519e249e6fd65a185e7bf against dev at 3366d05d03a3a1f9980541be349f6d8869a36686.
The workflow pin resolves the existing release tag to the verified release commit. The development command builds before Node startup, blocks stale execution after compilation failures, and keeps nodemon watching so a source correction recovers. Obsolete ts-node configuration and unused lock entries are removed; application source and runtime dependency records are unchanged.
Validation: frozen install, lint, typecheck, build, and all 35 tests passed. A bounded development smoke test verified initial compiled startup, rejection of a deliberate type error without stale startup, and automatic rebuild/restart after correction. Build Flow, including Node 22/24/26 validation, CodeQL execution, and container flow, completed successfully. Snyk and Trivy passed. Copilot's completed review found no code issues; its pending-check caveat is now settled. The exact-head dynamic Copilot run also completed, and no inline threads remain on this PR.
Limits: a healthy Redis-backed startup was not exercised locally. The separate CodeQL comparison check is neutral because the base has a legacy container.yml configuration absent from the current run, so it cannot determine newly introduced alerts. The container report flags the existing critical proxy-addr vulnerability CVE-2026-90711, outside this repair's unchanged runtime dependencies.
This supporting PR is conflict-free and ready for a merge decision. Promotion #92 remains blocked until this repair is integrated into dev, its checks are rerun, and the original finding is verified against the updated promotion head. No merge or approval was performed.
Fixes two confirmed blockers found while reviewing promotion #92. The current
devpush fails before creating jobs because the annotated Build Flow tag cannot resolve a nested workflow. Pinning to the verifiedv0.3.1release commit preserves its contents and gives nested workflows a commit reference.The TypeScript 7 update also breaks
ts-node@10.9.2initialization (review finding). The development command now reuses nodemon to watch source/config changes, runs the existing TypeScript build, and starts the compiled application with Node only after a successful build. Failed builds return exit1 so nodemon keeps watching; obsolete ts-node configuration/dependencies are removed. Application source and runtime dependency versions are unchanged.Validation: frozen install, lint (existing warnings only), typecheck, build, and all 35 tests passed with Bun 1.3.13. Coverage is 85.23% lines /84.27% functions. A bounded development smoke test verified progression into application environment validation, type-error rejection without running stale output, and restart after correcting the source. Filesystem events were tested in an isolated temporary copy outside the restricted sandbox; no Redis-backed healthy startup was exercised. At head
1e49f92d8aefd6049f5519e249e6fd65a185e7bf, Build Flow passed, including validation on Node 22/24/26, CodeQL execution, and container validation; Snyk and Trivy passed. Copilot review completed with no findings and there are no inline review threads. The separate CodeQL comparison result is neutral because the base branch has a legacycontainer.ymlconfiguration missing from the new run. The container report also flags a preexisting critical proxy-addr vulnerability (CVE-2026-90711); its runtime dependency record is unchanged by this repair.Promotion #92 remains blocked until this supporting fix is integrated into
devand the promotion is revalidated.