Repository navigation
chore(infra): sync consumers to published sdk 2.8.5, auth-express 2.2.8, payment-express 2.1.8 - #604
Merged
Merged
Conversation
…ent 2.1.8 The 2026-09-24 workflow_dispatch release published @bsv/sdk 2.8.5, @bsv/auth-express-middleware 2.2.8 and @bsv/payment-express-middleware 2.1.8 without the cascade sync job, so the standalone infrastructure manifests and locks were never reconciled and every image would keep shipping the previous middleware. Rewrite the direct @bsv/* caret floors to npm latest and patch-bump each component whose ranges changed, refresh every package-lock.json with npm 11 (--package-lock-only --ignore-scripts), then move the three published packages within their declared ranges so the wallet-toolbox and overlay-express consumers (wallet-infra, wab, overlay-server, chaintracks-server) resolve them too. chaintracks-server is patch-bumped by hand because its lock-only change must still be rebuilt by the infra release discover job. Regenerate docs/reference/stack-facts.md. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Program and scope
@bsv/sdk2.8.5,@bsv/auth-express-middleware2.2.8 and@bsv/payment-express-middleware2.1.8 (release run 36052862859, source40dad06dd)workflow_dispatch(non-cascade) release, sorelease.yaml'ssync-versionsjob was skipped and noautomation/sync-published-versionsPR reconciled the standalone infrastructure manifests and locks. Without this change every infra image keeps sdk ≤2.8.3 and auth-express-middleware 2.2.5, so the server-side half of the SDK 2.8.5 header-capacity compatibility fix never ships.packages/*,governance/*,.github/*,@bsv/overlay-topics(source 1.9.0 is still unpublished; the overlay-server floor stays at the published^1.8.4), wallet-toolbox / overlay-express floor bumps (their declared ranges already admit the new versions).e81611c0b(sync commit2bcc7af2f+ merge of origin/main90709a385;git diff origin/main --stat= the 17 synced files only)Impact
docs/reference/stack-facts.mdregenerated)Affected packages/services and intended patch versions (publication occurs only
through the release workflow after approval):
@bsv/wallet-toolbox ^2.14.0already current)StorageServeruses it)Method: direct
@bsv/*caret floors rewritten to npmdist-tags.latestand the component patch-bumped when a range changed (thescripts/sync-versions.mjsrule); every lock refreshed with npm 11npm install --package-lock-only --ignore-scripts; then a within-range transitive refreshnpm update @bsv/sdk @bsv/auth-express-middleware @bsv/payment-express-middleware --package-lock-only --ignore-scriptsso consumers that only receive the middleware through wallet-toolbox 2.14.0 / overlay-express 2.7.2 also resolve the published versions; chaintracks-server patch-bumped by hand because a lock-only change would otherwise be skipped by theinfra-release.yamldiscover job. No--legacy-peer-deps; every lock diff is limited to the three published packages (no other entries added, removed or moved; peer flags and lockfileVersion preserved).Verification
npm ci --ignore-scripts && npm rebuild <allowlisted> && npm audit --audit-level=high && npm run build/lint/test --if-presentfor all 8 infra projects: every step exit 0 for 7 projects; wabnpm testexits 1 locally (23/23 Jest suites fail to load thesqlite3native binding on macOS arm64 / Node 24). Re-running the identical steps against the pre-change HEAD manifest+lock reproduces the same failure, and the sqlite3 version is unchanged, so it is environmental; CI rebuilds sqlite3 on Linux.docker buildfor all 7 image components (local arch): all exit 0; each image's/app/node_modulescarries sdk 2.8.5, auth-express-middleware 2.2.8, payment-express-middleware 2.1.8 (overlay-server has no payment middleware)node scripts/check-versions.mjs: cleannode scripts/generate-stack-facts.mjs --check,pnpm docs:facts:check: cleanpnpm format:root: cleanpnpm health:check: exit 0 (42 projects, 0 contract findings, 0 control errors; one pre-existing expired maintenance exception warning unrelated to this change)pnpm lint: exit 0compatibility, public API, artifacts, dependencies, docs, and operations
scope-based skip is expected and validated by the merge gate
Maintainer decisions recorded
npm update <three first-party packages> --package-lock-only --ignore-scripts, not from the untargetednpm install --package-lock-onlythe automation runs.docs/reference/release-operations.md§4 item 3 asks reviewers of the generated sync PR to "confirm lock refreshes name no ad hoc package"; this human-authored PR names exactly the three packages the protected release just published, per §5 ("update and review its manifest and committed lock"). The alternative (direct-range-only) would leave wallet-infra'sStorageServeron auth-express-middleware 2.2.5 until wallet-toolbox republishes with a raised floor.--max-http-header-size=512000with nginxlarge_client_header_buffers 4 16k; wallet-infra's nginx uses default header buffers and the other services run Node's default 16 KiB total header limit. Aligning those limits with the SDK 2.8.5 client capacity is an operator decision tracked as a separate follow-up.governance/package-release-notes.json/docs/reference/package-api-migrations.mdreconciliation for 2.8.5 / 2.2.8 / 2.1.8 is owned by BotBoard [BotBoard][closed] ty-everett / Codex — consumer releases held for upstream payment fix #596 (PR docs: record verified SDK 2.8.5 and middleware patches #602) and intentionally not duplicated here.Security and dependencies
audit results were reviewed
governance/package-release-notes.json)(including accepted or false-positive issue states) and zero unreviewed hotspots;
Sonar's aggregate
Quality Gate passedverdict alone is not merge evidenceand removal condition (none added)
--ignore-scripts; Dockerfiles unchanged)Dependency evidence
governance/package-release-notes.jsonentries for sdk 2.8.5 (HTTP client header capacity ×4, BRC-105 proof headers, Peer general-payload policy), auth-express-middleware 2.2.8 (removes middleware header byte/count ceilings; HTTP layer owns transport capacity; requires sdk 2.8.5) and payment-express-middleware 2.1.8 (removes payment-header size rejection;maxPaymentHeaderBytesignored). Servers must run 2.2.8 / 2.1.8 to accept the larger signed headers 2.8.5 clients now send.@bsv/sdk ^2.8.5satisfied everywhere by the single deduped sdk 2.8.5; payment 2.1.8 peer^2.1.6; wallet-toolbox 2.14.0 peer^2.8.0; enginesnode >=24 <25unchanged.@bsv/sdk, one auth, one payment entry per lock; no nested duplicates.npm audit --audit-level=highclean per project (see Verification); no source change for CodeQL.npm test --if-present(see Verification).Release and operations
controlling program (infra component patch bumps included; no npm packages affected)
infra/v<release-id>;infra-release.yamlwill queue exactly these 7 components (their new versions are absent from GHCR) and attach SBOM/provenance/signature; existing immutable tags remain the rollback path. Migration guidance from the middleware releases: transport header limits are now the HTTP server / edge's responsibility (maxRequestBytesno longer caps received headers;maxPaymentHeaderBytesis ignored) — operators with restrictive proxies may need to raise header limits.docs/reference/stack-facts.mdregenerated; infra components have no changelog)Completion evidence
passing checks, resolved alerts, measurements, or an approved exception
guidance are current or concretely not applicable
being handed to another contributor as “complete”
restriction is assumed
🤖 Generated with Claude Code