Repair main: dependency conflict, dropped tracing wiring, PendingTx model, strict-mode and lint errors, docs and audit gates - #369
Merged
EmmanuelOchaje merged 8 commits intoSep 27, 2026
Conversation
…isma CLI advisory
✅ Deploy Preview for stellarticketsbackend ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #368
mainhas been red on every job since #367 merged (19e56d2). This PR gets thetest,docs-checkandmigration-lintinputs back to green and restores the code that merge dropped. Each commit is one concern so it can be reviewed, or reverted, on its own.Commits
@nestjs/swaggerpinned to^11.4.7(the newest release whose peers are Nest 11), the five@opentelemetry/*dependencies from Add opt-in OpenTelemetry tracing hooks #365 put back,@nestjs/platform-expressbumped to^11.2.6(pullsmulter2.4.0, closing four high advisories), lockfile regenerated.src/main.tsis the pre-merge bootstrap (dotenv,startTracing()before any Nest import, CSP directives, JSON body limit) with feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367's additions layered on through the same dynamic-import block:CORS_ORIGINS,GlobalExceptionFilter, Swagger outside production.src/app.module.tsgets itsTracingShutdownServiceimport back.20260925090000_add_pending_txcolumn for column, plus thependingTxsrelation onUser.scanner-device.guard.ts, which now ignores a non-stringticketIdparam instead of failing to compile.JSON_BODY_LIMIT,CSP_DIRECTIVESandCACHE_TTL_SECONDSwere read by code but missing fromenv.validation.ts, which is whatdocs:checkflags.docs/CONFIGURATION.mdand the four missing Bruno requests are generator output.@Catch()with noHttpExceptionbranch turned every 404, 403 and validation 400 into500 INTERNAL_ERRORin production. HttpExceptions now keep their status and Nest's body shape; three tests added. This is the one change here that is not a restoration; call it out if you would rather have it in its own PR.ResponseCacheInterceptorthrough the existingpassthroughoption; the capacity-lock spec joins the tagged-template chunks before looking forFOR UPDATE.npm auditlists a package that is only vulnerable through a dependency with the dependency's name invia, not an advisory id, socheck-audit.jscould never allowlistprismaor@prisma/config. It now walks those names down to the root advisory.deepmerge-ts(GHSA-ggr8-5vv4-36mx) is allowlisted with the reason in the file: only the Prisma CLI's config loader reaches it, and no Prisma 6.x ships the fixed 8.x line.@Transformcallbacks ({ value: unknown }), typed jest mocks and captured call arguments, rewroteBigIntSerializerInterceptor.serializeBigIntsoverunknown, and typed the filters'Request/Response. Same test cases, same runtime behaviour.Evidence (Node 22.23.3, clean
npm cifrom the new lockfile)npm cinpx tsc --noEmitnpx eslint "src/**/*.ts"npx jest --coveragenpm run buildnpm run docs:checknpm run audit:checkNot run locally:
e2e-testandmigration-lintneed Postgres, which this machine does not have. The schema change is a verbatim restore of the model the existing migration was generated from, somigrate diffshould report no drift; please let the workflow confirm.Out of scope
test/*.e2e-spec.tscarry 29 eslint errors of the sameno-unsafe-*kind. CI lintssrc/**only, so they are not a gate; happy to follow up.src/common/filters/domain-exception.filter.tsis no longer registered anywhere after feat: add global exception filter, CORS_ORIGINS validation, and Swagger #367 (the global filter handlesDomainError). Left in place; deleting it is a separate decision.extends, so everyconfirm-*request indocs/bruno/lackssignedXdr. Tracked in the follow-up PR that documents the API.