Skip to content

main is red since the swagger merge: npm ci, tsc, eslint, jest, docs-check and audit all fail #368

Description

@Majormaxx

Summary

Every CI job on main has failed since the merge of #367 (commit 19e56d2 on 2026-09-26). The last green run on main was 5124b03 (2026-09-23, #323). The test job never gets past npm ci, so tsc, eslint, jest and build results are hidden behind it.

What is broken, with the reason for each

  1. npm ci fails with ERESOLVE. feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367 added @nestjs/swagger@^12.0.2, which requires @nestjs/common@^12, while the project is on Nest 11. This is why every job that installs dependencies is red (test, e2e-test, docker-build, migration-lint).
  2. The merge of feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367 dropped code from main. Compared with main before the merge (88a69be), 19e56d2 removed the five @opentelemetry/* dependencies from package.json, the import 'dotenv/config' and import { startTracing } lines from src/main.ts (the startTracing() call is still there), the TracingShutdownService import from src/app.module.ts (the provider is still listed), and the CSP / JSON_BODY_LIMIT handling from Add security improvements: CSP config, body size limits, response caching, Dockerfile hardening #366. tsc reports Cannot find name 'startTracing' and Cannot find name 'TracingShutdownService'.
  3. PendingTx is gone from prisma/schema.prisma but src/pending-tx/ and the migration 20260925090000_add_pending_tx still exist. tsc fails on prisma.pendingTx, and prisma migrate diff --from-migrations --to-schema-datamodel would report drift.
  4. Strict-mode type errors left behind by ff2bd06 ("strict": true): three properties without definite assignment (is-bigint-string.decorator.spec.ts, is-stellar-public-key.decorator.spec.ts, update-resale-price.dto.ts), 'G' + 'A' * 55 in transfer-ticket.dto.spec.ts, a KeyObject typing in offline-token.service.spec.ts, deletedAt typed optional in test/factories, and request.params.ticketId (string | string[]) in scanner-device.guard.ts. 19 errors in total.
  5. Two failing unit suites: events.controller.spec.ts (32 tests) cannot resolve ResponseCacheInterceptor's CACHE_STORE dependency, and tickets.service.spec.ts asserts FOR UPDATE on the first chunk of a tagged template that now has an interpolation.
  6. eslint "src/**/*.ts" reports 127 errors, mostly no-unsafe-* in specs and in @Transform(({ value }) => ...) callbacks, plus the unresolved types from items 2 and 3.
  7. npm run docs:check fails: CACHE_TTL_SECONDS, JSON_BODY_LIMIT and CSP_DIRECTIVES are in .env.example but not in env.validation.ts, and the Bruno collection is missing the four soft-delete / restore requests.
  8. npm run audit:check fails on multer (via @nestjs/platform-express 11.1.28; fixed in 11.2.6) and on deepmerge-ts via @prisma/config (no fix in any Prisma 6.x; the script also cannot allowlist it because it only reads advisory ids from direct findings).
  9. Separate from the merge damage: GlobalExceptionFilter (added in feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367) uses @Catch() without a branch for HttpException, so with useGlobalFilters in main.ts every NotFoundException, ForbiddenException and ValidationPipe 400 is returned as 500 INTERNAL_ERROR. The e2e suite does not register the filter, which is why it did not catch this.

How to reproduce

git checkout 19e56d2
npm ci                      # ERESOLVE
npm install --legacy-peer-deps && npx prisma generate
npx tsc --noEmit            # 19 errors
npx eslint "src/**/*.ts"    # 127 errors
npx jest                    # 2 suites / 33 tests failing
npm run docs:check          # env table + Bruno collection out of date
npm run audit:check         # 5 findings at or above high

A fix for all nine items is in the linked pull request.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions