Skip to content

chore: pin esbuild to latest stable 0.28.1#24

Merged
BigSimmo merged 5 commits into
mainfrom
codex/esbuild-audit-fix
Jun 14, 2026
Merged

chore: pin esbuild to latest stable 0.28.1#24
BigSimmo merged 5 commits into
mainfrom
codex/esbuild-audit-fix

Conversation

@BigSimmo

Copy link
Copy Markdown
Owner

Summary

  • Address remaining high-severity npm audit finding for esbuild by pinning esbuild to 0.28.1 via npm override.
  • Regenerated package-lock.json and verified lint/typecheck/build/test/format/audit pass without framework changes.

Checks

  • npm run lint
  • npm run typecheck
  • npm run build
  • npm run test
  • npm run format:check
  • npm audit --audit-level=high

Notes

  • No dependency or behavior changes beyond esbuild version pinning.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@BigSimmo
BigSimmo merged commit 7db26a1 into main Jun 14, 2026
8 of 11 checks passed
@BigSimmo
BigSimmo deleted the codex/esbuild-audit-fix branch June 14, 2026 11:04
BigSimmo pushed a commit that referenced this pull request Jul 22, 2026
- Managed-alternative setup now says scope to UPDATE events only (do not tick
  INSERT) in the concrete instruction, not just a later warning — an INSERT
  webhook re-introduces the upload race.
- outstanding-issues #25: the base-URL GUC is mandatory per environment, not
  optional (the trigger no-ops without it), so the activation checklist can't
  leave the trigger inert.

Both are consistency fixes for earlier changes; neither touches the #24 row or
next-id marker (the ledger-collision surface vs #1066).

Docs-only.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BHMgBiXbH4Q5tUC7WxoyaX
BigSimmo added a commit that referenced this pull request Jul 22, 2026
BigSimmo pushed a commit that referenced this pull request Jul 22, 2026
- Renumber the webhook ledger rows #24-#27 -> #25-#28 (next-id 029) so they
  no longer collide with #1066's #24 (WebKit e2e). Per the consolidation
  decision, #1065 lands and the duplicate Codex webhook-doc PRs are closed;
  #1066 stays as a separate item.
- Scope the "receiver 500 -> retries" claim in the receiver-behaviour bullet:
  it only holds for a caller that actually retries, and neither documented path
  (raw net.http_post trigger or UPDATE-only managed webhook) does, so a failed
  clear can leave reindex_requested stuck true; recover via clear-then-flip.

Docs-only.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BHMgBiXbH4Q5tUC7WxoyaX
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant