Commit Graph
3 Commits
Author SHA1 Message Date
JMR-devandClaude Opus 4.8 52ce6e9aca #36 Security: patch vulnerable transitive deps form-data + uuid
Force patched versions of two vulnerable transitive dev-tooling deps
flagged by Dependabot. Both are dev-only (pulled in transitively by
wrangler / @usebruno/cli) and are not part of the Go/Wasm Worker:

- form-data 4.0.4 -> 4.0.6  (HIGH, CRLF injection; vuln >=4.0.0 <4.0.6)
- uuid      10.0.0 -> 14.0.1 (MEDIUM, buffer bounds; vuln <11.1.1)

The pnpm overrides live in pnpm-workspace.yaml (the `overrides:` key)
rather than package.json's `pnpm.overrides` because pnpm 11 no longer
reads the "pnpm" field in package.json (it warns and ignores it). This
sits alongside the existing allowBuilds config in the same file. The
lockfile was regenerated so form-data resolves to a single 4.0.6 and
uuid to 14.0.1 (the >=11.1.1 override resolves to the latest published
uuid, which is well above the vulnerable <11.1.1 range).

Verified locally:
- pnpm install and pnpm install --frozen-lockfile exit 0
- pnpm run test:api (Bruno suite) passes 8/8 against go devserver
- pnpm exec wrangler --version -> 4.106.0

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 15:42:41 -05:00
JMR-devandClaude Opus 4.8 b31455f1c3 #7 Approve protobufjs build script so pnpm install exits 0
@usebruno/cli (the API-test runner added in this PR) pulls in protobufjs,
whose postinstall build script pnpm 11 leaves un-approved by default. That
makes `pnpm install` exit non-zero (ERR_PNPM_IGNORED_BUILDS), which also
aborts `pnpm exec` / `pnpm run` via their verify-deps-before-run precheck
and would break CI's pnpm install once this lands on main.

Add protobufjs to the existing allowBuilds allowlist in pnpm-workspace.yaml
(same mechanism already used for esbuild/sharp/workerd). With it, pnpm
install exits 0 and the Bruno OpenCollection YAML suite runs green through
the pnpm wrapper (pnpm exec bru run / pnpm run test:api), 8/8 tests passing
against `go run ./cmd/devserver`.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 14:02:04 -05:00
Jason RossandClaude Opus 4.8 499bf7f655 Bootstrap Go module + Cloudflare Worker build tooling (#21)
Initialize the Go module and the Go -> Cloudflare Workers (TinyGo/Wasm) build
path, structured so `go test` and a local dev server run on plain Go without
TinyGo, while the real Wasm entrypoint is isolated behind build tags.

- go.mod/go.sum: module github.com/JMR-dev/LibreMail-Bug-Report-Ingest (Go 1.26),
  requiring github.com/syumai/workers.
- internal/handler: build-tag-free core http.Handler (GET / and GET /healthz,
  JSON responses, 404/405 handling) with net/http/httptest unit tests.
- cmd/devserver: plain net/http server mounting the core handler for local dev
  without TinyGo (listens on :8787, override with ADDR).
- worker/main.go: Cloudflare Workers (Wasm) entrypoint behind
  //go:build js && wasm, wiring the same handler via github.com/syumai/workers;
  excluded from host builds/tests.
- package.json + pnpm-lock.yaml + pnpm-workspace.yaml: wrangler dev dependency
  managed with pnpm, with toolchain build scripts approved.
- wrangler.jsonc: name=libremail-bug-report-ingest, main=./build/worker.mjs,
  build via `pnpm run build` (TinyGo).
- README: "Build & run locally" section with exact commands and the rationale
  for the TinyGo + syumai/workers path.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:22:48 -05:00