Force patched versions of two vulnerable transitive dev-tooling deps flagged by Dependabot. Both are dev-only (pulled in transitively by wrangler / @usebruno/cli) and are not part of the Go/Wasm Worker: - form-data 4.0.4 -> 4.0.6 (HIGH, CRLF injection; vuln >=4.0.0 <4.0.6) - uuid 10.0.0 -> 14.0.1 (MEDIUM, buffer bounds; vuln <11.1.1) The pnpm overrides live in pnpm-workspace.yaml (the `overrides:` key) rather than package.json's `pnpm.overrides` because pnpm 11 no longer reads the "pnpm" field in package.json (it warns and ignores it). This sits alongside the existing allowBuilds config in the same file. The lockfile was regenerated so form-data resolves to a single 4.0.6 and uuid to 14.0.1 (the >=11.1.1 override resolves to the latest published uuid, which is well above the vulnerable <11.1.1 range). Verified locally: - pnpm install and pnpm install --frozen-lockfile exit 0 - pnpm run test:api (Bruno suite) passes 8/8 against go devserver - pnpm exec wrangler --version -> 4.106.0 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
LibreMail Bug Report Ingest
Server-side infrastructure for LibreMail's debug bug-report pipeline. This repo is intentionally separate from the Android app repo — it owns the Cloudflare Worker and infrastructure-as-code, not the client.
What this is
Per JMR-dev/LibreMail#11:
- The LibreMail app lets a user opt in to submitting a debug report (LibreMail#33).
- A Cloudflare Worker in this repo receives the report over HTTPS, best-effort scrubs PII, and stores it encrypted in a Cloudflare R2 bucket (#34).
- Every Friday at 17:00 (Central Time, DST-aware), a scheduled job publishes any report not manually removed as a GitHub issue on the LibreMail repo (#35).
Stack
- Worker: Go, compiled to WebAssembly with TinyGo and served through the
syumai/workersruntime adapter - Infrastructure as code: Pulumi (Go)
- Deployment: GitHub Actions
- Secrets/key custody: Cloudflare Secret Manager
- DNS: Google Cloud DNS
Build & run locally
The request-handling logic lives in internal/handler as plain, build-tag-free
Go, so it is unit-tested and run locally with the standard Go toolchain — no
TinyGo needed. Only the actual Wasm Worker build requires TinyGo.
Layout:
internal/handler/— the corehttp.Handler(health/hello endpoints). No build tags; all request logic and its tests live here.cmd/devserver/— a plainnet/httpserver that mounts the core handler for local dev without TinyGo.worker/— the Cloudflare Workers (Wasm) entrypoint, guarded by//go:build js && wasm, wiring the same core handler into the Workers runtime. Excluded from host builds and tests.
Test
go vet ./...
go test ./...
Run locally (no TinyGo)
go run ./cmd/devserver # listens on :8787; override with ADDR, e.g. ADDR=:9000
Then, from another shell:
$ curl -s localhost:8787/
{"service":"libremail-bug-report-ingest","status":"ok","message":"hello from the LibreMail bug-report ingest Worker"}
$ curl -s localhost:8787/healthz
{"status":"ok"}
This runs the exact handler the deployed Worker uses, minus the Workers runtime.
Build & run the real Worker (requires TinyGo)
Node tooling is managed with pnpm; wrangler is a dev dependency. The Wasm build uses TinyGo 0.41.1 on the Go 1.26 toolchain.
Temporary toolchain patch. TinyGo 0.41.1 and earlier vendor a
net/httpjs/wasm overlay (tinygo-org/net@e54965e) that fails to compile against Go 1.25+/1.26 witht.roundTrip undefined(see tinygo-org/tinygo#5467). CI applies the exact upstream fix (tinygo-org/net@1026408a, checked in as.ci/tinygo-net-roundtrip.patch) to the installed TinyGo before building. Building locally on Go 1.26 needs the same one-file patch until a TinyGo release later than 0.41.1 ships it, at which point the patch and the CI step are removed (tracked in #26).
pnpm install # install wrangler
pnpm run build # workers-assets-gen + TinyGo -> ./build/app.wasm + ./build/worker.mjs
pnpm exec wrangler dev # serve the Wasm Worker locally on :8787
pnpm exec wrangler deploy # deploy (CI only)
pnpm run build runs, verbatim:
go run github.com/syumai/workers/cmd/workers-assets-gen && tinygo build -o ./build/app.wasm -target wasm -no-debug ./worker
TinyGo is not required for tests or the dev server; it is needed only for the
Wasm build above and is installed in CI. The generated ./build/ output is
git-ignored.
Why TinyGo + syumai/workers
Cloudflare Workers execute WebAssembly, not native binaries, so Go must be
compiled to Wasm. Of the two options — the standard compiler's
GOOS=js GOARCH=wasm output or TinyGo — TinyGo emits far smaller modules that
sit comfortably inside the Worker size limit, which is why it is the standard
path for Go on Workers. The syumai/workers
package adapts Go's net/http handler model to the Workers fetch event, so a
single http.Handler runs unchanged on the dev server and in the deployed
Worker.
Status
Early bootstrap. See the project board and open issues for the current breakdown of work.