Skip to content

chore(infra): sync consumers to published sdk 2.8.5, auth-express 2.2.8, payment-express 2.1.8 - #604

Merged
sirdeggen merged 2 commits into
mainfrom
worktree-infra-sync-published-deps
Sep 24, 2026
Merged

sirdeggen merged 2 commits into
mainfrom
worktree-infra-sync-published-deps

Conversation

@sirdeggen

Copy link
Copy Markdown
Contributor

Keep this pull request in draft until local validation is complete. After
every push, wait for all applicable checks on the exact head to finish and
fix every failure before requesting review or calling the work complete.

Program and scope

  • Tracker or issue: BotBoard #601 (division agreed with #596)
  • Program gate(s) advanced: infrastructure consumer reconciliation after the verified publication of @bsv/sdk 2.8.5, @bsv/auth-express-middleware 2.2.8 and @bsv/payment-express-middleware 2.1.8 (release run 36052862859, source 40dad06dd)
  • Why this change is needed: that publication was a workflow_dispatch (non-cascade) release, so release.yaml's sync-versions job was skipped and no automation/sync-published-versions PR reconciled the standalone infrastructure manifests and locks. Without this change every infra image keeps sdk ≤2.8.3 and auth-express-middleware 2.2.5, so the server-side half of the SDK 2.8.5 header-capacity compatibility fix never ships.
  • Explicitly out of scope: packages/*, governance/*, .github/*, @bsv/overlay-topics (source 1.9.0 is still unpublished; the overlay-server floor stays at the published ^1.8.4), wallet-toolbox / overlay-express floor bumps (their declared ranges already admit the new versions).
  • Exact head SHA reviewed: e81611c0b (sync commit 2bcc7af2f + merge of origin/main 90709a385; git diff origin/main --stat = the 17 synced files only)

Impact

  • No public package source or manifest changed
  • Public package source or manifest changed; affected packages are listed below
  • Infrastructure source, dependency, image, or deployment configuration changed
  • Public API, exports, types, runtime targets, or browser/mobile behavior changed
  • Security-sensitive boundary changed
  • Documentation or examples changed (docs/reference/stack-facts.md regenerated)

Affected packages/services and intended patch versions (publication occurs only
through the release workflow after approval):

Service Version Direct range changes Lock moves
chaintracks-server 1.1.22 → 1.1.23 none (@bsv/wallet-toolbox ^2.14.0 already current) sdk 2.8.0 → 2.8.5, auth 2.2.5 → 2.2.8, payment 2.1.7 → 2.1.8 (transitive via wallet-toolbox)
@bsv/messagebox-server 1.1.45 → 1.1.46 sdk ^2.8.3 → ^2.8.5, auth ^2.2.5 → ^2.2.8, payment ^2.1.7 → ^2.1.8 same three
@bsv/overlay-express-examples 2.1.40 → 2.1.41 sdk ^2.8.2 → ^2.8.5 sdk, auth 2.2.5 → 2.2.8 (transitive via overlay-express)
@bsv/uhrp-lite 0.1.41 → 0.1.42 sdk, auth, payment same three
@bsv/uhrp-storage-server 0.2.42 → 0.2.43 sdk, auth, payment same three
notifier (uhrp-server-cloud-bucket/notifier) 1.0.2 → 1.0.3 sdk ^2.8.2 → ^2.8.5 sdk
@bsv/wab-server 1.8.5 → 1.8.6 sdk ^2.8.2 → ^2.8.5 sdk, auth, payment (transitive via wallet-toolbox)
@bsv/wallet-infra 2.0.44 → 2.0.45 sdk ^2.8.2 → ^2.8.5, payment ^2.1.7 → ^2.1.8 sdk, payment, auth 2.2.5 → 2.2.8 (transitive via wallet-toolbox; StorageServer uses it)

Method: direct @bsv/* caret floors rewritten to npm dist-tags.latest and the component patch-bumped when a range changed (the scripts/sync-versions.mjs rule); every lock refreshed with npm 11 npm install --package-lock-only --ignore-scripts; then a within-range transitive refresh npm update @bsv/sdk @bsv/auth-express-middleware @bsv/payment-express-middleware --package-lock-only --ignore-scripts so consumers that only receive the middleware through wallet-toolbox 2.14.0 / overlay-express 2.7.2 also resolve the published versions; chaintracks-server patch-bumped by hand because a lock-only change would otherwise be skipped by the infra-release.yaml discover job. No --legacy-peer-deps; every lock diff is limited to the three published packages (no other entries added, removed or moved; peer flags and lockfileVersion preserved).

Verification

  • Local commands and results:
    • npm ci --ignore-scripts && npm rebuild <allowlisted> && npm audit --audit-level=high && npm run build/lint/test --if-present for all 8 infra projects: every step exit 0 for 7 projects; wab npm test exits 1 locally (23/23 Jest suites fail to load the sqlite3 native binding on macOS arm64 / Node 24). Re-running the identical steps against the pre-change HEAD manifest+lock reproduces the same failure, and the sqlite3 version is unchanged, so it is environmental; CI rebuilds sqlite3 on Linux.
    • docker build for all 7 image components (local arch): all exit 0; each image's /app/node_modules carries sdk 2.8.5, auth-express-middleware 2.2.8, payment-express-middleware 2.1.8 (overlay-server has no payment middleware)
    • node scripts/check-versions.mjs: clean
    • node scripts/generate-stack-facts.mjs --check, pnpm docs:facts:check: clean
    • pnpm format:root: clean
    • pnpm health:check: exit 0 (42 projects, 0 contract findings, 0 control errors; one pre-existing expired maintenance exception warning unrelated to this change)
    • pnpm lint: exit 0
    • Adversarial review: 16 independent lens reviews (lock/policy + runtime/compat per component) and a completeness critic found no lock-graph defect; the two process notes they raised are recorded under "Maintainer decisions" below
  • Hosted CI run: pending on this head (the Infra matrix selects all 8 projects and builds the 7 Linux/amd64 images)
  • Conformance evidence: not applicable (no package source change)
  • Coverage delta: none (no source change)
  • Lint/typecheck delta: none
  • Browser/mobile/packed-consumer evidence: not applicable
  • Performance or bundle-size delta: none expected (patch releases of already-bundled dependencies)
  • I self-reviewed the complete diff for correctness, security,
    compatibility, public API, artifacts, dependencies, docs, and operations
  • All applicable checks are terminal and successful on the exact head; any
    scope-based skip is expected and validated by the merge gate

Maintainer decisions recorded

  1. Within-range transitive refresh. The lock moves for auth/payment in wallet-infra, wab, overlay-server and chaintracks-server come from a targeted npm update <three first-party packages> --package-lock-only --ignore-scripts, not from the untargeted npm install --package-lock-only the automation runs. docs/reference/release-operations.md §4 item 3 asks reviewers of the generated sync PR to "confirm lock refreshes name no ad hoc package"; this human-authored PR names exactly the three packages the protected release just published, per §5 ("update and review its manifest and committed lock"). The alternative (direct-range-only) would leave wallet-infra's StorageServer on auth-express-middleware 2.2.5 until wallet-toolbox republishes with a raised floor.
  2. Transport header capacity is not changed here. The middleware releases delegate header admission to the HTTP layer. uhrp-server-cloud-bucket already runs --max-http-header-size=512000 with nginx large_client_header_buffers 4 16k; wallet-infra's nginx uses default header buffers and the other services run Node's default 16 KiB total header limit. Aligning those limits with the SDK 2.8.5 client capacity is an operator decision tracked as a separate follow-up.
  3. Release-notes ledger. governance/package-release-notes.json / docs/reference/package-api-migrations.md reconciliation for 2.8.5 / 2.2.8 / 2.1.8 is owned by BotBoard [BotBoard][closed] ty-everett / Codex — consumer releases held for upstream payment fix #596 (PR docs: record verified SDK 2.8.5 and middleware patches #602) and intentionally not duplicated here.

Security and dependencies

  • No dependency or lockfile change
  • Changelog, runtime relevance, peer compatibility, transitive graph, and
    audit results were reviewed
  • CodeQL/negative tests cover any changed trust boundary (no trust-boundary source change; middleware behaviour change is upstream and documented in governance/package-release-notes.json)
  • The exact-head CodeQL analysis has no new alert
  • The exact-head repository quality gate reports zero new Sonar findings
    (including accepted or false-positive issue states) and zero unreviewed hotspots;
    Sonar's aggregate Quality Gate passed verdict alone is not merge evidence
  • No new override, advisory dismissal, quality suppression, or skipped test
  • Any temporary exception is registered with owner, evidence, review date,
    and removal condition (none added)
  • Workflow permissions and lifecycle-script behavior remain least privilege (locks refreshed with --ignore-scripts; Dockerfiles unchanged)

Dependency evidence

  • Release notes and necessity: governance/package-release-notes.json entries for sdk 2.8.5 (HTTP client header capacity ×4, BRC-105 proof headers, Peer general-payload policy), auth-express-middleware 2.2.8 (removes middleware header byte/count ceilings; HTTP layer owns transport capacity; requires sdk 2.8.5) and payment-express-middleware 2.1.8 (removes payment-header size rejection; maxPaymentHeaderBytes ignored). Servers must run 2.2.8 / 2.1.8 to accept the larger signed headers 2.8.5 clients now send.
  • Runtime, build, and peer compatibility: auth 2.2.8 peer @bsv/sdk ^2.8.5 satisfied everywhere by the single deduped sdk 2.8.5; payment 2.1.8 peer ^2.1.6; wallet-toolbox 2.14.0 peer ^2.8.0; engines node >=24 <25 unchanged.
  • Deduplicated lockfile: one @bsv/sdk, one auth, one payment entry per lock; no nested duplicates.
  • Audit and CodeQL: npm audit --audit-level=high clean per project (see Verification); no source change for CodeQL.
  • Package and consumer tests: per-project npm test --if-present (see Verification).
  • Bundle and performance impact: none.
  • Affected public package versions: none (consumers only).

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • Required npm patch bumps are included or intentionally deferred by the
    controlling program (infra component patch bumps included; no npm packages affected)
  • Image/SBOM/provenance/deployment/rollback impact is documented: after merge, tag infra/v<release-id>; infra-release.yaml will queue exactly these 7 components (their new versions are absent from GHCR) and attach SBOM/provenance/signature; existing immutable tags remain the rollback path. Migration guidance from the middleware releases: transport header limits are now the HTTP server / edge's responsibility (maxRequestBytes no longer caps received headers; maxPaymentHeaderBytes is ignored) — operators with restrictive proxies may need to raise header limits.
  • Documentation, changelog, migration, and operational guidance are current (docs/reference/stack-facts.md regenerated; infra components have no changelog)

Completion evidence

  • The linked tracker is updated only for work fully proved by merged code,
    passing checks, resolved alerts, measurements, or an approved exception
  • Review conversations are resolved
  • Documentation, changelog, migration notes, release notes, and operator
    guidance are current or concretely not applicable
  • No pending, failed, stale, cancelled, or unexpectedly skipped check is
    being handed to another contributor as “complete”
  • One qualified maintainer approval is sufficient; no last-pusher
    restriction is assumed

🤖 Generated with Claude Code

sirdeggen and others added 2 commits September 24, 2026 16:26
…ent 2.1.8

The 2026-09-24 workflow_dispatch release published @bsv/sdk 2.8.5, @bsv/auth-express-middleware 2.2.8 and @bsv/payment-express-middleware 2.1.8 without the cascade sync job, so the standalone infrastructure manifests and locks were never reconciled and every image would keep shipping the previous middleware.

Rewrite the direct @bsv/* caret floors to npm latest and patch-bump each component whose ranges changed, refresh every package-lock.json with npm 11 (--package-lock-only --ignore-scripts), then move the three published packages within their declared ranges so the wallet-toolbox and overlay-express consumers (wallet-infra, wab, overlay-server, chaintracks-server) resolve them too. chaintracks-server is patch-bumped by hand because its lock-only change must still be rebuilt by the infra release discover job. Regenerate docs/reference/stack-facts.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​bsv/​sdk@​2.8.3 ⏵ 2.8.574 +110010099 +180
Updatednpm/​@​bsv/​payment-express-middleware@​2.1.7 ⏵ 2.1.87610010097 +180

View full report

@sonarqubecloud

Copy link
Copy Markdown

@sirdeggen
sirdeggen merged commit b0a0699 into main Sep 24, 2026
48 checks passed
@sirdeggen
sirdeggen deleted the worktree-infra-sync-published-deps branch September 24, 2026 21:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant