Repository navigation
build(deps): Bump @fastify/static from 9.1.3 to 10.1.2 - #5
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@fastify/static](https://github.com/fastify/fastify-static) from 9.1.3 to 10.1.2. - [Release notes](https://github.com/fastify/fastify-static/releases) - [Commits](fastify/fastify-static@v9.1.3...v10.1.2) --- updated-dependencies: - dependency-name: "@fastify/static" dependency-version: 10.1.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
All three are security releases: fastify closes GHSA-w2qp-rph6-63g4 and GHSA-3m5p-2c4r-xxw2, @fastify/static closes GHSA-83w8-p2f5-377r and GHSA-8pvw-jcv7-9cmj. Redone by hand on main's lockfile instead of taking the three Dependabot branches (#5, #6, #8), all of which fail CI the same way: regenerating the lockfile drops the integrity of the xlsx entry, which resolves to the SheetJS CDN rather than the registry, and pnpm then refuses to install an unverified tarball. Starting from a correct lockfile and running a real pnpm install leaves that entry untouched. docs/development/dependencies.md records the trap and the repair, because it will arrive again with every npm bump Dependabot proposes. @fastify/static 10 breaks one thing, setHeaders receiving a FastifyReply instead of the raw response. app.ts registers the plugin with a root and nothing else, so it is not concerned — and the commit before this one put that path under test. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* test(server): the SPA fallback was never exercised STATIC_DIR defaults to empty, so @fastify/static was never registered in a test and the not-found handler that falls back to index.html was never reached — while production sets it on every boot. A deep link answering 404 for every student is a break the suite would have reported green. Four cases on a temporary static root: an asset is served, a deep link gets index.html so a reload keeps the page, the API prefixes keep their JSON 404, and a non-GET never receives the SPA. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * build(deps): fastify 5.12.1, @fastify/static 10.1.2, vitest 4.1.11 All three are security releases: fastify closes GHSA-w2qp-rph6-63g4 and GHSA-3m5p-2c4r-xxw2, @fastify/static closes GHSA-83w8-p2f5-377r and GHSA-8pvw-jcv7-9cmj. Redone by hand on main's lockfile instead of taking the three Dependabot branches (#5, #6, #8), all of which fail CI the same way: regenerating the lockfile drops the integrity of the xlsx entry, which resolves to the SheetJS CDN rather than the registry, and pnpm then refuses to install an unverified tarball. Starting from a correct lockfile and running a real pnpm install leaves that entry untouched. docs/development/dependencies.md records the trap and the repair, because it will arrive again with every npm bump Dependabot proposes. @fastify/static 10 breaks one thing, setHeaders receiving a FastifyReply instead of the raw response. app.ts registers the plugin with a root and nothing else, so it is not concerned — and the commit before this one put that path under test. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Yves Chevallier <nowox@x0x.ch> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Superseded by #28, merged as b0385fd, which carries this bump with a working lockfile. This PR could not be merged: regenerating the lockfile drops the |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
* test(web): give the async queries a budget that survives a loaded machine TeacherHome's first findByRole failed about two runs in three under `pnpm -r test`, which runs four workspaces at once. The page had rendered its header but not yet its cards: a React Query round trip through a stubbed fetch had simply not finished inside Testing Library's one-second default, which assumes a machine running this suite and nothing else. Nothing is slow on purpose and no query fails to land, so the fix is the budget, not the tests. The fragility predates the command palette suites — they only grew the dom project by seventy tests and made it visible, verified by running the workspace with those three files removed, which came back clean three times out of three. Five seconds leaves room for a loaded CI runner while keeping a genuinely broken expectation failing promptly. Five consecutive `pnpm -r test` runs are green. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * ci: configure Dependabot so one repair covers every security bump The repository had no Dependabot configuration, which means only security updates ran and each opened its own pull request. All three that piled up (#5, #6, #8) failed identically on the xlsx lockfile integrity, and all three needed the same manual repair. The trap is that adding a configuration file at all ENABLES version updates for the ecosystem it names, so the obvious fix would have made things worse: a weekly batch of version bumps is a weekly batch of broken lockfiles. `open-pull-requests-limit: 0` switches version updates off while leaving security pull requests untouched — they are explicitly not subject to that limit — and a group then collapses them into one pull request instead of one per package. That group carries `applies-to: security-updates`. Without it a group defaults to version updates, so it would have grouped nothing at all, silently. GitHub Actions and the Docker base image go the other way, with version updates on: neither touches the pnpm lockfile, so their pull requests merge as they arrive, and there is drift to close — actions/setup-node is pinned at v5 in one workflow and v6 in another. Majors of the node base image are ignored, because moving production to a new Node major is a decision taken with `engines` and the CI matrix; `ignore` never applies to security updates, so that costs nothing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Yves Chevallier <nowox@x0x.ch> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bumps @fastify/static from 9.1.3 to 10.1.2.
Release notes
Sourced from @fastify/static's releases.
... (truncated)
Commits
7a9d1c6Bumped v10.1.2878c72eMerge commit from forkaee1c2cci: pin actions to commit-hash (#601)3733059Bumped 10.1.1db4276fMerge commit from forkc68224edocs(readme): fix typos (#600)36c939dBumped v10.1.07c1121afeat: use@fastify/errorfor errors and add optionsuppressWarning(#599)c57d8bcfix: set Vary: Accept-Encoding for preCompressed responses (#586)babf6dfBumped v10.0.0You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.