Build(deps): Bump the npm-prod-minor group across 1 directory with 6 updates - #29
Closed
dependabot[bot] wants to merge 18 commits into
Closed
dependabot[bot] wants to merge 18 commits into
dependabot[bot] wants to merge 18 commits into
Conversation
Day 1 build. Includes: - Fastify HTTP server bootstrap with cors, sensible, multipart, and JWT plugins - Prisma 5 schema for SCORM 1.2 / 2004: tenants, API keys, courses, SCOs, learners, attempts, interactions, objectives, and runtime commit log - Multi-stage Docker image + docker-compose with Postgres 16 and Redis - Zod-validated environment configuration with pluggable storage adapter - GitHub Actions CI: typecheck, build, prisma schema validation, tests against a Postgres service container - Claude Code PR review workflow, CodeQL, dependency review, OSSF Scorecard - Dependabot for npm, actions, and docker - Issue + PR templates, SECURITY.md disclosure policy Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.0 to 2.4.3. - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@v2.4.0...v2.4.3) --- updated-dependencies: - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Requires paid Anthropic API usage, which is out of scope for this project right now. CodeQL, dependency review, and OSSF Scorecard remain as the automated review layer. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Dependabot now groups minor/patch updates per ecosystem and skips semver-major bumps. Majors will be taken deliberately as planned tech-debt PRs instead of arriving as an unmanageable storm on day one. tsconfig.json: baseUrl is deprecated in TS 6 and removed in TS 7. paths still resolves correctly without it (relative to tsconfig dir). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…f/scorecard-action-2.4.3 Build(deps): Bump ossf/scorecard-action from 2.4.0 to 2.4.3
tests/config/env.test.ts (14 tests): - Default application and numeric coercion for PORT and JWT_ATTEMPT_TTL_SECONDS - Cache + resetEnvForTests behavior - Required field validation (DATABASE_URL, JWT_SECRET) - JWT_SECRET min-length enforcement - LOG_LEVEL / NODE_ENV enum enforcement - S3 driver conditional requirements for region, bucket, and credentials tests/http/app.test.ts (9 tests): - /healthz and /readyz response shape - Health endpoints unprefixed (not under /api/v1) - /api/v1/ returns server name and version - Structured 404 for unknown routes and methods - CORS preflight passes Origin and credentials through - @fastify/jwt registration and sign/verify round-trip tsconfig.json now includes tests/ so typecheck covers them. tsconfig.build.json takes over rootDir + src-only include so the production build remains test-free. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
OSSF Scorecard's Token-Permissions check flags top-level write permissions because every job inherits them whether they need them or not. Moving security-events:write (codeql) and pull-requests:write (dependency-review) to the job blocks keeps the workflow-level token at contents:read. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
OSV reported a critical fast-jwt cluster (auth bypass via empty HMAC, JWT algorithm confusion, iss claim validation), high-severity fast-uri path traversal, and a moderate esbuild dev-server SSRF. All sit in the previous majors of fastify, @fastify/jwt, and vitest. fastify ^4.28.1 -> ^5.8.5 @fastify/cors ^9.0.1 -> ^11.2.0 @fastify/jwt ^8.0.1 -> ^10.1.0 @fastify/multipart ^8.3.0 -> ^10.0.0 @fastify/sensible ^5.6.0 -> ^6.0.4 vitest ^2.1.1 -> ^4.1.7 No source changes needed: the buildApp surface, plugin registration order, and inject()-based tests are all compatible with Fastify 5. typecheck, tests (23/23), and build are green. `npm audit` now reports zero vulnerabilities. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…pinned
The previous blanket ignore on semver-major bumps left this repo
unable to receive automated PRs for security-driven major upgrades
(the fast-jwt CVE cluster required @fastify/jwt 10, which required
fastify 5, which the blanket rule blocked).
New policy:
- npm: minor/patch grouped per dependency type (prod, dev) into two
PRs/week. Majors land as individual PRs so each can be reviewed on
its own. Exceptions:
@types/node — pinned to match the runtime major in package.json
and the Dockerfile base image
typescript — taken deliberately, not on a weekly schedule
- github-actions: minor/patch grouped. Majors individual.
- docker: node base image major stays pinned; everything else can
flow through.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Bumps [@prisma/client](https://github.com/prisma/prisma/tree/HEAD/packages/client) from 5.22.0 to 7.8.0. - [Release notes](https://github.com/prisma/prisma/releases) - [Commits](https://github.com/prisma/prisma/commits/7.8.0/packages/client) --- updated-dependencies: - dependency-name: "@prisma/client" dependency-version: 7.8.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ma/client-7.8.0 Build(deps): Bump @prisma/client from 5.22.0 to 7.8.0
@prisma/client jumped 5.22 -> 7.8 in isolation while the prisma CLI stayed pinned at ^5.20. That produces an ENOENT for generator-build/prisma_schema_build_bg.wasm at prisma generate time because the v7 client expects a schema-wasm shipped by the v7 CLI. Reverting restores both halves to 5.22, which is the last known-good combination. The next commit groups the two packages in .github/dependabot.yml so an automated PR can't split them again. This reverts commit aa6b3a8. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The Prisma CLI and @prisma/client share an internal schema-wasm contract, so a major bump to one without the other produces an ENOENT at generator-build time (already happened once and broke CI). Putting them in a single named group forces Dependabot to open a combined PR whenever either side updates, regardless of bump type. The group sits above npm-prod-minor / npm-dev-minor so it claims the packages first; the other groups still cover everything else. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Dependabot has already proposed @prisma/client 7.8.0 (via the merged-then-reverted PR #17), so its internal "already shipped" tracking now refuses to re-include the client in the prisma group. The group then proposes the prisma CLI alone, which produces the exact split-major mismatch we just fixed. Ignoring semver-major bumps for both prisma and @prisma/client takes the moving target away entirely. Prisma 6/7 will be taken deliberately as a single manual upgrade when the schema can be verified against the new client. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…route Implements the package ingestion pipeline that lets the engine accept and persist SCORM 1.2 and 2004 ZIP packages: - StorageAdapter interface + LocalStorage adapter (S3 to come later) - Streaming ZIP extractor with anti-zipbomb guards (per-entry / total-size / file-count caps + path-traversal rejection) - imsmanifest.xml parser that detects SCORM 1.2 vs 2004 2nd/3rd/4th, walks nested organization items, resolves identifierref to webcontent/sco resources, and surfaces title/description/keywords/mastery from LOM metadata - POST /api/v1/courses (multipart upload) and POST /api/v1/courses/validate routes, plus GET/DELETE list+detail handlers - API key auth plugin: sha256-hashed lookup against the ApiKey table, sets req.tenantId / req.apiKeyId for downstream handlers - buildApp now accepts injectable prisma + storage deps so tests can swap them for in-memory fakes without standing up Postgres Tests cover the parser (both SCORM versions, malformed manifests, asset-only packages), the zip extractor (path traversal, size caps, malformed buffers), the validate report, and the full upload route via Fastify inject with a mock Prisma + in-memory storage. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Addresses the OSSF Scorecard Pinned-Dependencies finding. Every `uses:` reference across CI, CodeQL, Dependency Review, Scorecard, and Release workflows now points at a full commit SHA with the version pinned in a trailing comment so a human reviewer (and Dependabot) can still see what's pinned. The Docker base image (node:20-alpine) is pinned by manifest-list digest in docker/Dockerfile. Dependabot is already configured for the github-actions and docker ecosystems in .github/dependabot.yml, so future updates arrive as reviewable PRs rather than silent floating-tag rolls. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- Bump version to 0.0.1 - Add publishConfig (public access + provenance) so the scoped package publishes correctly and is signed via OIDC in CI - Add repository, homepage, bugs, and keywords for the npm listing - Add MIT LICENSE - Add README with quick start, REST API summary, architecture, and roadmap Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…updates Bumps the npm-prod-minor group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@fastify/cors](https://github.com/fastify/fastify-cors) | `11.2.0` | `11.3.0` | | [@fastify/jwt](https://github.com/fastify/fastify-jwt) | `10.1.0` | `10.2.0` | | [@fastify/multipart](https://github.com/fastify/fastify-multipart) | `10.0.0` | `10.1.0` | | [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `5.8.0` | `5.10.0` | | [fastify](https://github.com/fastify/fastify) | `5.8.5` | `5.10.0` | | [yauzl](https://github.com/thejoshwolfe/yauzl) | `3.3.2` | `3.4.0` | Updates `@fastify/cors` from 11.2.0 to 11.3.0 - [Release notes](https://github.com/fastify/fastify-cors/releases) - [Commits](fastify/fastify-cors@v11.2.0...v11.3.0) Updates `@fastify/jwt` from 10.1.0 to 10.2.0 - [Release notes](https://github.com/fastify/fastify-jwt/releases) - [Commits](fastify/fastify-jwt@v10.1.0...v10.2.0) Updates `@fastify/multipart` from 10.0.0 to 10.1.0 - [Release notes](https://github.com/fastify/fastify-multipart/releases) - [Commits](fastify/fastify-multipart@v10.0.0...v10.1.0) Updates `fast-xml-parser` from 5.8.0 to 5.10.0 - [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases) - [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md) - [Commits](NaturalIntelligence/fast-xml-parser@v5.8.0...v5.10.0) Updates `fastify` from 5.8.5 to 5.10.0 - [Release notes](https://github.com/fastify/fastify/releases) - [Commits](fastify/fastify@v5.8.5...v5.10.0) Updates `yauzl` from 3.3.2 to 3.4.0 - [Commits](thejoshwolfe/yauzl@3.3.2...3.4.0) --- updated-dependencies: - dependency-name: "@fastify/cors" dependency-version: 11.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-prod-minor - dependency-name: "@fastify/jwt" dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-prod-minor - dependency-name: "@fastify/multipart" dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-prod-minor - dependency-name: fast-xml-parser dependency-version: 5.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-prod-minor - dependency-name: fastify dependency-version: 5.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-prod-minor - dependency-name: yauzl dependency-version: 3.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-prod-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/npm-prod-minor-476b682088
branch
August 5, 2026 19:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm-prod-minor group with 6 updates in the / directory:
11.2.011.3.010.1.010.2.010.0.010.1.05.8.05.10.05.8.55.10.03.3.23.4.0Updates
@fastify/corsfrom 11.2.0 to 11.3.0Release notes
Sourced from @fastify/cors's releases.
Commits
2c60caaBumped v11.3.0cf4986echore: bump@types/nodein the dev-dependencies-typescript group (#411)816d054test: remove remaining tap-style assertions from vary tests (#410)20507eachore(package.json): fix delvedor's personal url (#409)6fe85c4docs(readme): update request origin link (#408)57bdc65chore: bump fastify-plugin from 5.1.0 to 6.0.0 in the dependencies group (#407)a8ae57dchore: update depedabot setting4d34798chore(.gitattributes): retain binary file eol style (#402)675ebefrefactor(types): migrate from tsd to tstyche (#403)ef25e0bci: add lock-threads workflow (#401)Updates
@fastify/jwtfrom 10.1.0 to 10.2.0Release notes
Sourced from @fastify/jwt's releases.
Commits
b82ca2bBumped v10.2.0745b57cchore: bump@types/nodein the dev-dependencies-typescript group (#421)631539bdocs: fix broken linksadcc808chore(package.json): fix delvedor's personal url319f1d0chore(example): use https for url (#417)e4f9a03chore: bump@fastify/rate-limitfrom 10.3.0 to 11.0.0 (#416)7d2bd6fchore: bump fastify-plugin from 5.1.0 to 6.0.0 in the dependencies group (#415)ffe076echore: update depedabot setting3cba727fixes CVE-2026-44351 found in fast-jwt (#412)Updates
@fastify/multipartfrom 10.0.0 to 10.1.0Release notes
Sourced from @fastify/multipart's releases.
Commits
0a8ab66Bumped v10.1.0a9d53e5fix: update module version9b3bf89fix: do not end parts() iteration while busboy still holds undelivered parts ...45023e0chore: bump@types/nodein the dev-dependencies-typescript group (#629)77b563edocs: fix broken linksd7475dachore: bump@fastify/swagger-uifrom 5.2.6 to 6.0.0 (#626)ed56b6fchore: bump fastify-plugin from 5.1.0 to 6.0.0 in the dependencies group (#625)f79f996chore: update depedabot setting60e1b5cchore: use lf eol (#619)cddccd4refactor(types): migrate from tsd to tstyche (#617)Updates
fast-xml-parserfrom 5.8.0 to 5.10.0Release notes
Sourced from fast-xml-parser's releases.
Changelog
Sourced from fast-xml-parser's changelog.
... (truncated)
Commits
296b3325.10.075f7565update package guide2d8d1d0update detailse58e4ddupgrade: xml-naming v0.3.0, PEM v1.6.2, is-unsafe v2.0.0545e491Bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 (#848)5ea8aa1Bump actions/checkout from 6.0.3 to 7.0.0 (#849)93a09f15.9.39c1905eupdate strnum8d71292GitHub Actions workflow fixes (#844)784a044Harden GitHub Actions workflows (#841)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for fast-xml-parser since your current version.
Updates
fastifyfrom 5.8.5 to 5.10.0Release notes
Sourced from fastify's releases.
... (truncated)
Commits
94bcbccBumped v5.10.0c47975edocs: Update import for page consistency (#6771)82952b8docs: Logging.md with per-route log level info (#6627)6ac2e95fix: derive request.port from request.host (#6680)5f4871fperf: reduce per-request overhead in the request lifecycle (#6831)ec4bc66chore: Bump fast-json-stringify to v7 (#6800)d0b649ddocs: fix incorrect hook count in Hooks.md (eight -> ten) (#6825)826c807docs: fix incorrect defaults and code examples in Server.md (#6805)6f63ce9fix: use ContentType to detectjsonandcharsetin reply.send (#6830)75d74e1feat: introduce log controller layer (#6580)Updates
yauzlfrom 3.3.2 to 3.4.0Commits
f5798e1version 3.4.0632d650add promises API (#171)73b1ba5CONTRIBUTING.mdDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions