You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Every CI job on main has failed since the merge of #367 (commit 19e56d2 on 2026-09-26). The last green run on main was 5124b03 (2026-09-23, #323). The test job never gets past npm ci, so tsc, eslint, jest and build results are hidden behind it.
What is broken, with the reason for each
npm ci fails with ERESOLVE.feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367 added @nestjs/swagger@^12.0.2, which requires @nestjs/common@^12, while the project is on Nest 11. This is why every job that installs dependencies is red (test, e2e-test, docker-build, migration-lint).
PendingTx is gone from prisma/schema.prisma but src/pending-tx/ and the migration 20260925090000_add_pending_tx still exist. tsc fails on prisma.pendingTx, and prisma migrate diff --from-migrations --to-schema-datamodel would report drift.
Strict-mode type errors left behind by ff2bd06 ("strict": true): three properties without definite assignment (is-bigint-string.decorator.spec.ts, is-stellar-public-key.decorator.spec.ts, update-resale-price.dto.ts), 'G' + 'A' * 55 in transfer-ticket.dto.spec.ts, a KeyObject typing in offline-token.service.spec.ts, deletedAt typed optional in test/factories, and request.params.ticketId (string | string[]) in scanner-device.guard.ts. 19 errors in total.
Two failing unit suites:events.controller.spec.ts (32 tests) cannot resolve ResponseCacheInterceptor's CACHE_STORE dependency, and tickets.service.spec.ts asserts FOR UPDATE on the first chunk of a tagged template that now has an interpolation.
eslint "src/**/*.ts" reports 127 errors, mostly no-unsafe-* in specs and in @Transform(({ value }) => ...) callbacks, plus the unresolved types from items 2 and 3.
npm run docs:check fails:CACHE_TTL_SECONDS, JSON_BODY_LIMIT and CSP_DIRECTIVES are in .env.example but not in env.validation.ts, and the Bruno collection is missing the four soft-delete / restore requests.
npm run audit:check fails on multer (via @nestjs/platform-express 11.1.28; fixed in 11.2.6) and on deepmerge-ts via @prisma/config (no fix in any Prisma 6.x; the script also cannot allowlist it because it only reads advisory ids from direct findings).
Separate from the merge damage:GlobalExceptionFilter (added in feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367) uses @Catch() without a branch for HttpException, so with useGlobalFilters in main.ts every NotFoundException, ForbiddenException and ValidationPipe 400 is returned as 500 INTERNAL_ERROR. The e2e suite does not register the filter, which is why it did not catch this.
How to reproduce
git checkout 19e56d2
npm ci # ERESOLVE
npm install --legacy-peer-deps && npx prisma generate
npx tsc --noEmit # 19 errors
npx eslint "src/**/*.ts"# 127 errors
npx jest # 2 suites / 33 tests failing
npm run docs:check # env table + Bruno collection out of date
npm run audit:check # 5 findings at or above high
A fix for all nine items is in the linked pull request.
Summary
Every CI job on
mainhas failed since the merge of #367 (commit 19e56d2 on 2026-09-26). The last green run onmainwas 5124b03 (2026-09-23, #323). Thetestjob never gets pastnpm ci, so tsc, eslint, jest and build results are hidden behind it.What is broken, with the reason for each
npm cifails with ERESOLVE. feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367 added@nestjs/swagger@^12.0.2, which requires@nestjs/common@^12, while the project is on Nest 11. This is why every job that installs dependencies is red (test,e2e-test,docker-build,migration-lint).main. Compared withmainbefore the merge (88a69be),19e56d2removed the five@opentelemetry/*dependencies frompackage.json, theimport 'dotenv/config'andimport { startTracing }lines fromsrc/main.ts(thestartTracing()call is still there), theTracingShutdownServiceimport fromsrc/app.module.ts(the provider is still listed), and the CSP /JSON_BODY_LIMIThandling from Add security improvements: CSP config, body size limits, response caching, Dockerfile hardening #366.tscreportsCannot find name 'startTracing'andCannot find name 'TracingShutdownService'.PendingTxis gone fromprisma/schema.prismabutsrc/pending-tx/and the migration20260925090000_add_pending_txstill exist.tscfails onprisma.pendingTx, andprisma migrate diff --from-migrations --to-schema-datamodelwould report drift."strict": true): three properties without definite assignment (is-bigint-string.decorator.spec.ts,is-stellar-public-key.decorator.spec.ts,update-resale-price.dto.ts),'G' + 'A' * 55intransfer-ticket.dto.spec.ts, aKeyObjecttyping inoffline-token.service.spec.ts,deletedAttyped optional intest/factories, andrequest.params.ticketId(string | string[]) inscanner-device.guard.ts. 19 errors in total.events.controller.spec.ts(32 tests) cannot resolveResponseCacheInterceptor'sCACHE_STOREdependency, andtickets.service.spec.tsassertsFOR UPDATEon the first chunk of a tagged template that now has an interpolation.eslint "src/**/*.ts"reports 127 errors, mostlyno-unsafe-*in specs and in@Transform(({ value }) => ...)callbacks, plus the unresolved types from items 2 and 3.npm run docs:checkfails:CACHE_TTL_SECONDS,JSON_BODY_LIMITandCSP_DIRECTIVESare in.env.examplebut not inenv.validation.ts, and the Bruno collection is missing the four soft-delete / restore requests.npm run audit:checkfails onmulter(via@nestjs/platform-express11.1.28; fixed in 11.2.6) and ondeepmerge-tsvia@prisma/config(no fix in any Prisma 6.x; the script also cannot allowlist it because it only reads advisory ids from direct findings).GlobalExceptionFilter(added in feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367) uses@Catch()without a branch forHttpException, so withuseGlobalFiltersinmain.tseveryNotFoundException,ForbiddenExceptionandValidationPipe400 is returned as500 INTERNAL_ERROR. The e2e suite does not register the filter, which is why it did not catch this.How to reproduce
A fix for all nine items is in the linked pull request.