Skip to content

Commit d7cfde3

Browse files
committed
chore: sync branch base to main at 1.0.2
1 parent d50be03 commit d7cfde3

35 files changed

Lines changed: 1612 additions & 274 deletions

‎.github/dependabot.yml‎

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
version: 2
2+
updates:
3+
- package-ecosystem: github-actions
4+
directory: /
5+
schedule:
6+
interval: weekly
7+
day: monday
8+
open-pull-requests-limit: 10
9+
commit-message:
10+
prefix: ci
11+
groups:
12+
github-actions:
13+
patterns: ["*"]
14+
labels:
15+
- dependencies
16+
- github-actions
17+
18+
- package-ecosystem: npm
19+
directory: /
20+
schedule:
21+
interval: weekly
22+
day: monday
23+
open-pull-requests-limit: 10
24+
commit-message:
25+
prefix: chore
26+
prefix-development: chore
27+
include: scope
28+
groups:
29+
# Dev-only minor/patch — auto-merge candidates (vitest, typescript,
30+
# vite plugins). One PR keeps churn down.
31+
dev-deps-minor:
32+
dependency-type: development
33+
update-types: [minor, patch]
34+
# Runtime minor/patch — small surface (js-yaml only) but still group.
35+
prod-deps-minor:
36+
dependency-type: production
37+
update-types: [minor, patch]
38+
# All majors get their own PR per package — no grouping — so the
39+
# human review queue can evaluate them individually.
40+
labels:
41+
- dependencies
42+
- npm
43+
ignore:
44+
# Stay on a stable Node major; bump deliberately, not via dependabot.
45+
- dependency-name: "@types/node"
46+
update-types: [version-update:semver-major]

‎.github/workflows/ci.yml‎

Lines changed: 36 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,15 +6,49 @@ on:
66
push:
77
branches: [main]
88

9+
permissions:
10+
contents: read
11+
912
jobs:
1013
test:
1114
runs-on: ubuntu-latest
15+
timeout-minutes: 10
1216
steps:
1317
- uses: actions/checkout@v6
14-
- uses: actions/setup-node@v4
18+
- uses: actions/setup-node@v6
1519
with:
16-
node-version: 22.22.0
20+
node-version: 24.14.0
1721
cache: npm
1822
- run: npm ci
1923
- run: npx tsc --noEmit
2024
- run: npx vitest run --coverage --passWithNoTests
25+
26+
security:
27+
runs-on: ubuntu-latest
28+
timeout-minutes: 10
29+
steps:
30+
- uses: actions/checkout@v6
31+
with:
32+
fetch-depth: 0
33+
34+
- uses: actions/setup-node@v6
35+
with:
36+
node-version: 24.14.0
37+
cache: npm
38+
39+
- run: npm ci
40+
41+
# Dependency audit — fail on high/critical vulnerabilities
42+
- name: npm audit
43+
run: npm audit --audit-level=high
44+
45+
# Build output size gate — single-file HTML should stay under 150 KB
46+
- name: Build and check output size
47+
run: |
48+
npm run build
49+
size=$(stat -c%s dist/index.html)
50+
echo "Build output: ${size} bytes"
51+
if [ "$size" -gt 153600 ]; then
52+
echo "::error::Build output exceeds 150 KB (${size} bytes) — unexpected bloat"
53+
exit 1
54+
fi
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
name: Dependabot auto-merge
2+
3+
on:
4+
pull_request_target:
5+
types: [opened, synchronize, reopened, ready_for_review]
6+
7+
permissions:
8+
contents: write
9+
pull-requests: write
10+
11+
jobs:
12+
automerge:
13+
if: github.event.pull_request.user.login == 'dependabot[bot]'
14+
runs-on: ubuntu-latest
15+
timeout-minutes: 5
16+
steps:
17+
- name: Fetch Dependabot metadata
18+
id: meta
19+
uses: dependabot/fetch-metadata@v2.4.0
20+
with:
21+
github-token: ${{ secrets.GITHUB_TOKEN }}
22+
23+
# Auto-merge minor and patch updates only — major updates go to a
24+
# human review queue. github-actions and dev-only npm minor/patch are
25+
# the safest categories and historically clean every time CI passes.
26+
- name: Enable auto-merge for safe updates
27+
if: |
28+
steps.meta.outputs.update-type == 'version-update:semver-minor' ||
29+
steps.meta.outputs.update-type == 'version-update:semver-patch'
30+
env:
31+
PR_URL: ${{ github.event.pull_request.html_url }}
32+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
33+
run: gh pr merge --auto --squash "$PR_URL"

‎.github/workflows/deploy.yml‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,19 +16,20 @@ concurrency:
1616
jobs:
1717
deploy:
1818
runs-on: ubuntu-latest
19+
timeout-minutes: 10
1920
environment:
2021
name: github-pages
2122
url: ${{ steps.deployment.outputs.page_url }}
2223
steps:
2324
- uses: actions/checkout@v6
24-
- uses: actions/setup-node@v4
25+
- uses: actions/setup-node@v6
2526
with:
26-
node-version: 22.22.0
27+
node-version: 24.14.0
2728
cache: npm
2829
- run: npm ci
2930
- run: npm run build
3031
- uses: actions/configure-pages@v5
31-
- uses: actions/upload-pages-artifact@v3
32+
- uses: actions/upload-pages-artifact@v4
3233
with:
3334
path: dist
3435
- id: deployment

‎.github/workflows/pre-commit.yml‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
name: Pre-commit
2+
3+
on:
4+
push:
5+
branches: [main]
6+
pull_request:
7+
branches: [main]
8+
9+
jobs:
10+
pre-commit:
11+
runs-on: ubuntu-latest
12+
timeout-minutes: 10
13+
steps:
14+
- uses: actions/checkout@v6
15+
- uses: actions/setup-python@v5
16+
with:
17+
python-version: "3.x"
18+
- uses: pre-commit/action@v3.0.1

‎.github/workflows/prerelease.yml‎

Lines changed: 39 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -3,20 +3,33 @@ name: Pre-release
33
on:
44
push:
55
branches: [main]
6+
# Skip pre-release for changes that don't affect the built artifact.
7+
paths-ignore:
8+
- '**.md'
9+
- '.github/dependabot.yml'
10+
- '.github/ISSUE_TEMPLATE/**'
11+
- '.github/PULL_REQUEST_TEMPLATE/**'
12+
- '.coderabbit.yaml'
13+
- '.gitleaks.toml'
14+
- '.pre-commit-config.yaml'
15+
- '.yamllint.yml'
16+
- '.gitignore'
17+
- 'LICENSE'
618

719
permissions:
820
contents: write
921

1022
jobs:
1123
prerelease:
1224
runs-on: ubuntu-latest
25+
timeout-minutes: 10
1326
steps:
1427
- uses: actions/checkout@v6
1528
with:
1629
fetch-depth: 0
17-
- uses: actions/setup-node@v4
30+
- uses: actions/setup-node@v6
1831
with:
19-
node-version: 22.22.0
32+
node-version: 24.14.0
2033
cache: npm
2134

2235
- name: Get current version
@@ -29,31 +42,44 @@ jobs:
2942
id: prerelease
3043
env:
3144
BASE_VERSION: ${{ steps.version.outputs.version }}
45+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
46+
REPO: ${{ github.repository }}
3247
run: |
33-
LATEST=$(git tag -l "v${BASE_VERSION}-pre.*" --sort=-version:refname | head -n1)
48+
# Derive the next number from existing RELEASES (incl. drafts + already
49+
# published immutable releases), NOT git tags. Under immutable releases a
50+
# pre-release tag can be permanently reserved in the release ledger while
51+
# never materializing as a git ref, so git-tag-based numbering collides on
52+
# the same number every run. The releases list always reflects burned tags.
53+
LATEST=$(gh api "repos/${REPO}/releases" --paginate \
54+
--jq ".[].tag_name | select(startswith(\"v${BASE_VERSION}-pre.\"))" \
55+
| sed "s|^v${BASE_VERSION}-pre.||" | sort -n | tail -n1)
3456
if [ -z "$LATEST" ]; then
3557
NUM=1
3658
else
37-
NUM=$(echo "$LATEST" | sed "s/v${BASE_VERSION}-pre\.\([0-9]*\)/\1/")
38-
NUM=$((NUM + 1))
59+
NUM=$((LATEST + 1))
3960
fi
4061
TAG="v${BASE_VERSION}-pre.${NUM}"
4162
echo "tag=$TAG" >> "$GITHUB_OUTPUT"
4263
4364
- run: npm ci
4465
- run: npm run build
45-
- run: cp dist/index.html compose-sanitizer.html
66+
- run: cp dist/index.html docker-compose-debugger.html
4667

47-
- name: Create pre-release tag
48-
env:
49-
TAG: ${{ steps.prerelease.outputs.tag }}
50-
run: |
51-
git tag "$TAG"
52-
git push origin "$TAG"
5368

69+
# The repo has immutable releases enabled. softprops/action-gh-release
70+
# creates and publishes in one step, which means the asset upload races
71+
# against the immutable lockdown and fails. Create as draft, upload the
72+
# asset, then publish in a follow-up step.
5473
- uses: softprops/action-gh-release@v2
5574
with:
5675
tag_name: ${{ steps.prerelease.outputs.tag }}
57-
files: compose-sanitizer.html
76+
files: docker-compose-debugger.html
5877
generate_release_notes: true
5978
prerelease: true
79+
draft: true
80+
81+
- name: Publish pre-release
82+
env:
83+
TAG: ${{ steps.prerelease.outputs.tag }}
84+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
85+
run: gh release edit "$TAG" --repo "${{ github.repository }}" --draft=false

‎.github/workflows/release.yml‎

Lines changed: 14 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,17 +10,27 @@ permissions:
1010
jobs:
1111
release:
1212
runs-on: ubuntu-latest
13+
timeout-minutes: 10
1314
steps:
1415
- uses: actions/checkout@v6
15-
- uses: actions/setup-node@v4
16+
- uses: actions/setup-node@v6
1617
with:
17-
node-version: 22.22.0
18+
node-version: 24.14.0
1819
cache: npm
1920
- run: npm ci
2021
- run: npm run build
21-
- run: cp dist/index.html compose-sanitizer.html
22+
- run: cp dist/index.html docker-compose-debugger.html
23+
# Immutable releases require draft-first so assets can be attached
24+
# before the release is locked.
2225
- uses: softprops/action-gh-release@v2
2326
with:
24-
files: compose-sanitizer.html
27+
files: docker-compose-debugger.html
2528
generate_release_notes: true
2629
prerelease: ${{ contains(github.ref, '-') }}
30+
draft: true
31+
32+
- name: Publish release
33+
env:
34+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
35+
TAG: ${{ github.ref_name }}
36+
run: gh release edit "$TAG" --repo "${{ github.repository }}" --draft=false

‎.github/workflows/stable-release.yml‎

Lines changed: 26 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -14,11 +14,12 @@ permissions:
1414
jobs:
1515
release:
1616
runs-on: ubuntu-latest
17+
timeout-minutes: 10
1718
steps:
1819
- uses: actions/checkout@v6
19-
- uses: actions/setup-node@v4
20+
- uses: actions/setup-node@v6
2021
with:
21-
node-version: 22.22.0
22+
node-version: 24.14.0
2223
cache: npm
2324

2425
- name: Validate version format
@@ -42,13 +43,16 @@ jobs:
4243
- name: Update package.json version
4344
env:
4445
VERSION: ${{ inputs.version }}
45-
run: npm version "$VERSION" --no-git-tag-version
46+
# `npm version` errors when the requested version equals the current
47+
# (which happens when the version was bumped in a PR before the
48+
# release workflow runs). `npm pkg set` is idempotent.
49+
run: npm pkg set "version=$VERSION"
4650

4751
- run: npm ci
4852
- run: npx tsc --noEmit
4953
- run: npx vitest run --passWithNoTests
5054
- run: npm run build
51-
- run: cp dist/index.html compose-sanitizer.html
55+
- run: cp dist/index.html docker-compose-debugger.html
5256

5357
- name: Commit version bump and tag
5458
env:
@@ -57,13 +61,29 @@ jobs:
5761
git config user.name "github-actions[bot]"
5862
git config user.email "github-actions[bot]@users.noreply.github.com"
5963
git add package.json package-lock.json
60-
git commit -m "chore: release v${VERSION}"
64+
# If the version was already bumped in a PR (so package.json/lock
65+
# are unchanged here) skip the commit. The tag and push still need
66+
# to run.
67+
if ! git diff --cached --quiet; then
68+
git commit -m "chore: release v${VERSION}"
69+
else
70+
echo "package.json already at v${VERSION}; skipping bump commit"
71+
fi
6172
git tag "v${VERSION}"
6273
git push origin main --follow-tags
6374
75+
# Immutable releases require draft-first so assets can be attached
76+
# before the release is locked.
6477
- uses: softprops/action-gh-release@v2
6578
with:
6679
tag_name: v${{ inputs.version }}
67-
files: compose-sanitizer.html
80+
files: docker-compose-debugger.html
6881
generate_release_notes: true
6982
prerelease: false
83+
draft: true
84+
85+
- name: Publish release
86+
env:
87+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
88+
TAG: v${{ inputs.version }}
89+
run: gh release edit "$TAG" --repo "${{ github.repository }}" --draft=false

‎.gitleaks.toml‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
# Gitleaks configuration
2+
# https://github.com/gitleaks/gitleaks
3+
4+
title = "docker-compose-debugger gitleaks config"
5+
6+
[allowlist]
7+
description = "Global allowlist"
8+
paths = [
9+
'''node_modules/''',
10+
'''dist/''',
11+
'''coverage/''',
12+
'''package-lock\.json''',
13+
]

0 commit comments

Comments
 (0)