chore(deps): update postgres docker tag to v18 - #21
Closed
renovate[bot] wants to merge 337 commits into
Closed
renovate[bot] wants to merge 337 commits into
renovate[bot] wants to merge 337 commits into
Conversation
Add three workflow templates for internal dogfood launch: - Deploy Notification: event trigger on deploy.succeeded → Slack - New User Onboarding: event trigger on member.added → welcome email - Daily Audit Digest: cron → query Chronicle → email summary
These files were referenced by committed code but never tracked, breaking Docker/CI builds that clone from git.
- Add requestId to GraphQL context via X-Request-Id header or generated ID - Improve authentication plugin logic - Update OAuth routes - Fix cron and polling trigger handling - Refresh integration catalog - Update workflow template seeds - Misc server and webhook handler cleanup
…orkflow helper
Replace scattered inline Hatchet.init() blocks and hatchet.event.push("workflow:execute") calls in api.ts, webhooks.ts, cron.ts, and polling.ts with the shared dispatchWorkflow helper. Remove dispatch.ts from Knip ignore list now that it is wired into callers.
Make command nullable and add transport (default stdio), url, and headers columns to support SSE and HTTP remote transport configurations.
POST /api/v1/plugins/upload accepts multipart form-data with a WASM binary, computes SHA256, uploads to S3 (PLUGIN_STORAGE_BUCKET), injects the public URL into the manifest, and inserts the plugin record into pluginTable.
- Extract `validateApiKey` into `src/lib/auth/apiKey.ts` and import it in both `api.ts` and `routes/plugins.ts` to eliminate duplication - Reject requests where `manifest.wasm` is pre-populated (reserved field) - Add `PLUGIN_STORAGE_BASE_URL` env var for S3-compatible store URL override - Move `S3Client` instantiation inside the handler after the bucket guard - Add 10MB file size limit to the WASM upload field - Add success-path `logger.info` after plugin insert
…module-level S3Client
…reation and monthly runs
All features open on all tiers per open-source parity model. Plugin creation now only enforces the max_plugins count limit, not a plan-tier feature flag. Removes unused isFeatureEnabled helper.
renovate
Bot
force-pushed
the
renovate/postgres-18.x
branch
from
March 31, 2026 17:53
b4c26da to
0831418
Compare
GATEKEEPER_ -> AUTH_, AETHER_ -> BILLING_. Core infra env vars should describe their use case, not their internal product name.
renovate
Bot
force-pushed
the
renovate/postgres-18.x
branch
from
April 4, 2026 07:20
0831418 to
9ba9a73
Compare
…e and quote events Route mantle.invoice.* and mantle.quote.* events to MyFi's /api/webhooks/mantle endpoint for automated accounting
The platform has grown beyond 16 internal subscriptions, hitting the previous default
Reads all user-organization memberships from the local DB (synced from Gatekeeper) and writes the corresponding authorization tuples to the Warden PDP. Supports --dry-run and --delete-orphans flags, following the same pattern as Runa's reconciliation scripts. Usage: bun authz:reconcile
renovate
Bot
force-pushed
the
renovate/postgres-18.x
branch
from
April 9, 2026 16:03
9ba9a73 to
88ea645
Compare
Add three REST endpoints for external systems (e.g. Hatchet cron) to check and repair user-organization membership tuple drift between the DB and Warden PDP: - GET /api/v1/authz/tuples (expected tuples from DB) - GET /api/v1/authz/drift (diff expected vs PDP) - POST /api/v1/authz/reconcile (write missing, optionally delete orphans)
The API was blindly setting status='running' after dispatchWorkflow returned, but the worker can complete the run before the dispatch call returns (races of 100ms or less for simple workflows). This overwrote completed/failed terminal states back to running, leaving runs stuck forever in the UI. Add WHERE status='pending' guard so the update only fires if the worker hasn't already transitioned the state.
…er seats - Security: drizzle-orm 0.45.1 to 0.45.2 (SQL injection fix) - Deps: graphql 16.13.2, @sentry/bun 10.48.0, @hatchet-dev/typescript-sdk 1.21.0, graphql-yoga 5.21.0, @tanstack/query-core 5.97.0, @temporalio/client 1.16.0 - Auth: propagate idpUserId from Gatekeeper API keys so Warden checks run for API key holders (not just session users) - Billing: hard-enforce MAX_USERS entitlement in IDP webhook handler (was warn-only, now rejects when seat limit exceeded) - Tests: add regression tests for API key authZ propagation and seat enforcement - Chore: add packageManager field, rename WARDEN_SYNC to AUTHZ_SYNC in locks, fix graphql type dedup in schema generation script
renovate
Bot
force-pushed
the
renovate/postgres-18.x
branch
from
April 10, 2026 21:00
88ea645 to
15afad2
Compare
renovate
Bot
force-pushed
the
renovate/postgres-18.x
branch
from
April 10, 2026 22:00
15afad2 to
f5412a8
Compare
Add Warden authorization checks to 18 read endpoints and billing usage metering (recordUsage) to 20 mutation endpoints. Upgrade dependencies (graphile to stable 1.0.0). Align with Omni template conventions (package.json metadata, changeset config, husky). Note: tsc --noEmit has pre-existing PostGraphile v5 type errors from the graphile RC to stable upgrade that need separate resolution.
renovate
Bot
force-pushed
the
renovate/postgres-18.x
branch
from
April 11, 2026 02:44
f5412a8 to
a361e71
Compare
Add type annotations for graphile 1.0.0 stable API changes: - Cast fieldArgs.getRaw() returns (AnyInputStep to Step<any>) - Annotate Drizzle where callback parameters - Bridge GraphQLSchema type between graphql and graphql-yoga
…illing exports Close the authorization gap for event subscriptions by adding a GraphQL plugin that enforces admin+ role and max_subscriptions plan limits on create/update/delete mutations. Also export checkUsage from the billing module for worker-side pre-execution limit checks.
Add AUTHZ_API_URL and AUTHZ_SERVICE_KEY to all env config mocks so the warden/client.ts re-export does not fail when Bun runs multiple test files in the same process. Expand the wardenSyncPoller mock to preserve checkPermission behavior and prevent it from stubbing out the authorize wrapper tests. Add env config mock to execution.test.ts to prevent the real assertEnv from throwing.
…upgrade deps Add execution limit check to function invocation to prevent billing bypass. Add Warden authorize to DLQ list/stats endpoints. Add CLA workflow, changeset tooling, and source-code validation tests for enforcement coverage.
renovate
Bot
force-pushed
the
renovate/postgres-18.x
branch
from
April 11, 2026 18:58
a361e71 to
99731cd
Compare
The dep upgrade resolved grafast ^1.0.0-rc.8 to stable 1.0.0, which has breaking changes in the planning lifecycle (currentLayerPlan). Pin to exact 1.0.0-rc.8 until PostGraphile v5 reaches stable.
renovate
Bot
force-pushed
the
renovate/postgres-18.x
branch
from
April 11, 2026 23:24
99731cd to
251905d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
16-alpine→18-alpineConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.