Node.js 24.20.0 and various tool upgrades - #81

Merged
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps
Aug 31, 2026
Merged

Node.js 24.20.0 and various tool upgrades#81
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps

Conversation

@solsson

Copy link
Copy Markdown
Collaborator

No description provided.

solssonand others added 10 commits August 31, 2026 07:57
Two patch releases, and with them undici 7.28.0 -> 7.29.0 in the runtime that
serves every global fetch() in a node service. That undici release is
security-only: GHSA-4cwx-7wf7-3272 (Cache-Control parser, cross-user cache
disclosure / parse crash) plus four medium advisories in Blob H1 request
bodies, no-cache/private parsing, the retry interceptor's Content-Length and
setCookie sanitization.
checkit already overrides the *npm* undici to 7.29.0 for the first of those
(pnpm-workspace.yaml), but an override cannot reach the copy bundled in node,
which is the one behind fetch(). Measured in the images rather than inferred:
gcr.io/distroless/nodejs24-debian13:nonroot pinned since 2026-07-14
node 24.18.0, undici 7.28.0
the same tag today
node 24.20.0, undici 7.29.0
Not a fix for anything observed. rest-v1 hit UND_ERR_SOCKET "other side closed"
against kkv-userstate on 2026-08-31, and no undici release addresses that -
upstream's position is that a peer may close whenever it likes and idempotent
requests should be retried.
The digest is the OCI index, 8 manifests, same shape as the pin it replaces.
docker-base pins the same node tag in node/Dockerfile and bases builder-base on
this runner, so it follows once this is built.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three minor releases behind. Checksums generated by y-bin-download-next, which
verifies each one against the .sha256 the release publishes rather than trusting
the bytes it just downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Crosses 1.0, so worth naming what is in it: v1.0.1 "platforms OCI
normalization" and v1.1.0 "add push, mirror and registry-proxy, with optional
direct-to-storage upload". There is no v1.0.0 release; 0.9.2 is followed
directly by 1.0.1. Neither note lists a breaking change - no config schema
change, no removed or renamed flag - so checkit's `contain build -x
--file-output checkit-images.json --platforms-env-require` should be unaffected.
Unverified here, and the reason to watch the first builds: "platforms OCI
normalization" is the one change that touches what --platforms-env-require
reads, and the release notes do not say how.
Checksums from y-bin-download-next. contain publishes no .sha256, so these are
hashes of the downloaded artifacts rather than something cross-checked against
the release - unlike skaffold in the previous commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One patch release. Checksums from y-bin-download-next; the npm tarballs carry no
published .sha256 to cross-check against, so these are hashes of what was
downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jq moved org years ago; the download template still pointed at stedolan/jq,
which GitHub redirects, so it kept working and hid the fact that we were two
minors behind on a repo we were not really watching. 1.8.x is only published
under jqlang/jq. Asset names are unchanged (jq-macos-arm64, jq-linux-amd64 and
so on), so only the org in the URL moves.
The 1.8 line also publishes sha256sum.txt, so this adds the sha256 template
alongside the download one. y-bin-download-next then verifies each hash against
what the release published instead of hashing whatever it downloaded - the same
treatment skaffold gets, and the reason all four checksums here are stronger
evidence than the ones they replace.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch on the 3 line, staying there. Helm 4.2.4 exists and is a separate
decision, not a version bump.
Note this pin is not what the runner image ships: runner.Dockerfile installs
helm from the buildkite helm-debian apt repo instead, a documented workaround
for get.helm.sh SSL failures in GitHub Actions, and copies it in as
y-helm-<version>-bin. This pin governs the on-demand download path. The two
sources are worth reconciling; not in this commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three patches. Hashes of the downloaded artifacts: yq publishes checksums, but
in a format that needs checksums_hashes_order to parse, which is why the sha256
template is commented out in this block rather than missing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch. Hashes of the downloaded artifacts; cue publishes no per-asset .sha256
for y-bin-download-next to check against.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One buildkit minor. This is the client only; the buildkitd running in-cluster is
pinned separately, and buildkit supports a version skew between them, but if
builds start behaving oddly that pairing is the first thing to check.
Hashes of the downloaded artifacts; the release publishes no per-asset .sha256.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dead since the script it was written for stopped existing. fe5e0f8 added it in
2026-04-22 to replace kubectl-yconverge's `_find_cue_dir` bash heuristic with a
real walk of the kustomize tree; 9b60ed6 then dropped those provisioning
scripts for the y-cluster binary, and bin/kubectl-yconverge is now a symlink to
`cluster`. Nothing under ~/Yolean has referred to y-kustomize-traverse since -
not ystack, not checkit, not docker-base - and the runner image never baked it
in, so the pin has been carrying a download nobody performs.
The traversal itself is not obsolete, it moved. ccec90e in y-cluster,
"extract traverse package, rename module to y-cluster", turned this project into
that one: the walk lives in pkg/kustomize/traverse and reaches the CLI as
`y-cluster yconverge`, which aggregates CUE files reachable through kustomize
resources/components/bases. For the traversal on its own, without applying
anything, that is `y-cluster yconverge --print-deps`, which prints the
topological order. y-cluster is already pinned in this file as `cluster`.
Which is also why this is a removal and not a bump. The rename means
"kustomize-traverse latest" resolves to y-cluster v0.5.0, but that release
publishes only y-cluster_v0.5.0_* assets - no kustomize-traverse-*.tar.gz - so
raising the version here would have produced a 404 on first download. v0.1.0 is
the last release that this URL can ever resolve.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@solsson
solsson merged commit a7db143 into mainAug 31, 2026
2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@solsson
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Node.js 24.20.0 and various tool upgrades - #81

Merged
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps
Aug 31, 2026
Merged

Node.js 24.20.0 and various tool upgrades#81
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps

Conversation

@solsson

Copy link
Copy Markdown
Collaborator

No description provided.

solssonand others added 10 commits August 31, 2026 07:57
Two patch releases, and with them undici 7.28.0 -> 7.29.0 in the runtime that
serves every global fetch() in a node service. That undici release is
security-only: GHSA-4cwx-7wf7-3272 (Cache-Control parser, cross-user cache
disclosure / parse crash) plus four medium advisories in Blob H1 request
bodies, no-cache/private parsing, the retry interceptor's Content-Length and
setCookie sanitization.
checkit already overrides the *npm* undici to 7.29.0 for the first of those
(pnpm-workspace.yaml), but an override cannot reach the copy bundled in node,
which is the one behind fetch(). Measured in the images rather than inferred:
gcr.io/distroless/nodejs24-debian13:nonroot pinned since 2026-07-14
node 24.18.0, undici 7.28.0
the same tag today
node 24.20.0, undici 7.29.0
Not a fix for anything observed. rest-v1 hit UND_ERR_SOCKET "other side closed"
against kkv-userstate on 2026-08-31, and no undici release addresses that -
upstream's position is that a peer may close whenever it likes and idempotent
requests should be retried.
The digest is the OCI index, 8 manifests, same shape as the pin it replaces.
docker-base pins the same node tag in node/Dockerfile and bases builder-base on
this runner, so it follows once this is built.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three minor releases behind. Checksums generated by y-bin-download-next, which
verifies each one against the .sha256 the release publishes rather than trusting
the bytes it just downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Crosses 1.0, so worth naming what is in it: v1.0.1 "platforms OCI
normalization" and v1.1.0 "add push, mirror and registry-proxy, with optional
direct-to-storage upload". There is no v1.0.0 release; 0.9.2 is followed
directly by 1.0.1. Neither note lists a breaking change - no config schema
change, no removed or renamed flag - so checkit's `contain build -x
--file-output checkit-images.json --platforms-env-require` should be unaffected.
Unverified here, and the reason to watch the first builds: "platforms OCI
normalization" is the one change that touches what --platforms-env-require
reads, and the release notes do not say how.
Checksums from y-bin-download-next. contain publishes no .sha256, so these are
hashes of the downloaded artifacts rather than something cross-checked against
the release - unlike skaffold in the previous commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One patch release. Checksums from y-bin-download-next; the npm tarballs carry no
published .sha256 to cross-check against, so these are hashes of what was
downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jq moved org years ago; the download template still pointed at stedolan/jq,
which GitHub redirects, so it kept working and hid the fact that we were two
minors behind on a repo we were not really watching. 1.8.x is only published
under jqlang/jq. Asset names are unchanged (jq-macos-arm64, jq-linux-amd64 and
so on), so only the org in the URL moves.
The 1.8 line also publishes sha256sum.txt, so this adds the sha256 template
alongside the download one. y-bin-download-next then verifies each hash against
what the release published instead of hashing whatever it downloaded - the same
treatment skaffold gets, and the reason all four checksums here are stronger
evidence than the ones they replace.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch on the 3 line, staying there. Helm 4.2.4 exists and is a separate
decision, not a version bump.
Note this pin is not what the runner image ships: runner.Dockerfile installs
helm from the buildkite helm-debian apt repo instead, a documented workaround
for get.helm.sh SSL failures in GitHub Actions, and copies it in as
y-helm-<version>-bin. This pin governs the on-demand download path. The two
sources are worth reconciling; not in this commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three patches. Hashes of the downloaded artifacts: yq publishes checksums, but
in a format that needs checksums_hashes_order to parse, which is why the sha256
template is commented out in this block rather than missing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch. Hashes of the downloaded artifacts; cue publishes no per-asset .sha256
for y-bin-download-next to check against.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One buildkit minor. This is the client only; the buildkitd running in-cluster is
pinned separately, and buildkit supports a version skew between them, but if
builds start behaving oddly that pairing is the first thing to check.
Hashes of the downloaded artifacts; the release publishes no per-asset .sha256.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dead since the script it was written for stopped existing. fe5e0f8 added it in
2026-04-22 to replace kubectl-yconverge's `_find_cue_dir` bash heuristic with a
real walk of the kustomize tree; 9b60ed6 then dropped those provisioning
scripts for the y-cluster binary, and bin/kubectl-yconverge is now a symlink to
`cluster`. Nothing under ~/Yolean has referred to y-kustomize-traverse since -
not ystack, not checkit, not docker-base - and the runner image never baked it
in, so the pin has been carrying a download nobody performs.
The traversal itself is not obsolete, it moved. ccec90e in y-cluster,
"extract traverse package, rename module to y-cluster", turned this project into
that one: the walk lives in pkg/kustomize/traverse and reaches the CLI as
`y-cluster yconverge`, which aggregates CUE files reachable through kustomize
resources/components/bases. For the traversal on its own, without applying
anything, that is `y-cluster yconverge --print-deps`, which prints the
topological order. y-cluster is already pinned in this file as `cluster`.
Which is also why this is a removal and not a bump. The rename means
"kustomize-traverse latest" resolves to y-cluster v0.5.0, but that release
publishes only y-cluster_v0.5.0_* assets - no kustomize-traverse-*.tar.gz - so
raising the version here would have produced a 404 on first download. v0.1.0 is
the last release that this URL can ever resolve.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@solsson
solsson merged commit a7db143 into mainAug 31, 2026
2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@solsson
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Node.js 24.20.0 and various tool upgrades - #81

Merged
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps
Aug 31, 2026
Merged

Node.js 24.20.0 and various tool upgrades#81
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps

Conversation

@solsson

Copy link
Copy Markdown
Collaborator

No description provided.

solssonand others added 10 commits August 31, 2026 07:57
Two patch releases, and with them undici 7.28.0 -> 7.29.0 in the runtime that
serves every global fetch() in a node service. That undici release is
security-only: GHSA-4cwx-7wf7-3272 (Cache-Control parser, cross-user cache
disclosure / parse crash) plus four medium advisories in Blob H1 request
bodies, no-cache/private parsing, the retry interceptor's Content-Length and
setCookie sanitization.
checkit already overrides the *npm* undici to 7.29.0 for the first of those
(pnpm-workspace.yaml), but an override cannot reach the copy bundled in node,
which is the one behind fetch(). Measured in the images rather than inferred:
gcr.io/distroless/nodejs24-debian13:nonroot pinned since 2026-07-14
node 24.18.0, undici 7.28.0
the same tag today
node 24.20.0, undici 7.29.0
Not a fix for anything observed. rest-v1 hit UND_ERR_SOCKET "other side closed"
against kkv-userstate on 2026-08-31, and no undici release addresses that -
upstream's position is that a peer may close whenever it likes and idempotent
requests should be retried.
The digest is the OCI index, 8 manifests, same shape as the pin it replaces.
docker-base pins the same node tag in node/Dockerfile and bases builder-base on
this runner, so it follows once this is built.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three minor releases behind. Checksums generated by y-bin-download-next, which
verifies each one against the .sha256 the release publishes rather than trusting
the bytes it just downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Crosses 1.0, so worth naming what is in it: v1.0.1 "platforms OCI
normalization" and v1.1.0 "add push, mirror and registry-proxy, with optional
direct-to-storage upload". There is no v1.0.0 release; 0.9.2 is followed
directly by 1.0.1. Neither note lists a breaking change - no config schema
change, no removed or renamed flag - so checkit's `contain build -x
--file-output checkit-images.json --platforms-env-require` should be unaffected.
Unverified here, and the reason to watch the first builds: "platforms OCI
normalization" is the one change that touches what --platforms-env-require
reads, and the release notes do not say how.
Checksums from y-bin-download-next. contain publishes no .sha256, so these are
hashes of the downloaded artifacts rather than something cross-checked against
the release - unlike skaffold in the previous commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One patch release. Checksums from y-bin-download-next; the npm tarballs carry no
published .sha256 to cross-check against, so these are hashes of what was
downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jq moved org years ago; the download template still pointed at stedolan/jq,
which GitHub redirects, so it kept working and hid the fact that we were two
minors behind on a repo we were not really watching. 1.8.x is only published
under jqlang/jq. Asset names are unchanged (jq-macos-arm64, jq-linux-amd64 and
so on), so only the org in the URL moves.
The 1.8 line also publishes sha256sum.txt, so this adds the sha256 template
alongside the download one. y-bin-download-next then verifies each hash against
what the release published instead of hashing whatever it downloaded - the same
treatment skaffold gets, and the reason all four checksums here are stronger
evidence than the ones they replace.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch on the 3 line, staying there. Helm 4.2.4 exists and is a separate
decision, not a version bump.
Note this pin is not what the runner image ships: runner.Dockerfile installs
helm from the buildkite helm-debian apt repo instead, a documented workaround
for get.helm.sh SSL failures in GitHub Actions, and copies it in as
y-helm-<version>-bin. This pin governs the on-demand download path. The two
sources are worth reconciling; not in this commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three patches. Hashes of the downloaded artifacts: yq publishes checksums, but
in a format that needs checksums_hashes_order to parse, which is why the sha256
template is commented out in this block rather than missing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch. Hashes of the downloaded artifacts; cue publishes no per-asset .sha256
for y-bin-download-next to check against.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One buildkit minor. This is the client only; the buildkitd running in-cluster is
pinned separately, and buildkit supports a version skew between them, but if
builds start behaving oddly that pairing is the first thing to check.
Hashes of the downloaded artifacts; the release publishes no per-asset .sha256.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dead since the script it was written for stopped existing. fe5e0f8 added it in
2026-04-22 to replace kubectl-yconverge's `_find_cue_dir` bash heuristic with a
real walk of the kustomize tree; 9b60ed6 then dropped those provisioning
scripts for the y-cluster binary, and bin/kubectl-yconverge is now a symlink to
`cluster`. Nothing under ~/Yolean has referred to y-kustomize-traverse since -
not ystack, not checkit, not docker-base - and the runner image never baked it
in, so the pin has been carrying a download nobody performs.
The traversal itself is not obsolete, it moved. ccec90e in y-cluster,
"extract traverse package, rename module to y-cluster", turned this project into
that one: the walk lives in pkg/kustomize/traverse and reaches the CLI as
`y-cluster yconverge`, which aggregates CUE files reachable through kustomize
resources/components/bases. For the traversal on its own, without applying
anything, that is `y-cluster yconverge --print-deps`, which prints the
topological order. y-cluster is already pinned in this file as `cluster`.
Which is also why this is a removal and not a bump. The rename means
"kustomize-traverse latest" resolves to y-cluster v0.5.0, but that release
publishes only y-cluster_v0.5.0_* assets - no kustomize-traverse-*.tar.gz - so
raising the version here would have produced a 404 on first download. v0.1.0 is
the last release that this URL can ever resolve.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@solsson
solsson merged commit a7db143 into mainAug 31, 2026
2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@solsson
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Node.js 24.20.0 and various tool upgrades - #81

Merged
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps
Aug 31, 2026
Merged

Node.js 24.20.0 and various tool upgrades#81
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps

Conversation

@solsson

Copy link
Copy Markdown
Collaborator

No description provided.

solssonand others added 10 commits August 31, 2026 07:57
Two patch releases, and with them undici 7.28.0 -> 7.29.0 in the runtime that
serves every global fetch() in a node service. That undici release is
security-only: GHSA-4cwx-7wf7-3272 (Cache-Control parser, cross-user cache
disclosure / parse crash) plus four medium advisories in Blob H1 request
bodies, no-cache/private parsing, the retry interceptor's Content-Length and
setCookie sanitization.
checkit already overrides the *npm* undici to 7.29.0 for the first of those
(pnpm-workspace.yaml), but an override cannot reach the copy bundled in node,
which is the one behind fetch(). Measured in the images rather than inferred:
gcr.io/distroless/nodejs24-debian13:nonroot pinned since 2026-07-14
node 24.18.0, undici 7.28.0
the same tag today
node 24.20.0, undici 7.29.0
Not a fix for anything observed. rest-v1 hit UND_ERR_SOCKET "other side closed"
against kkv-userstate on 2026-08-31, and no undici release addresses that -
upstream's position is that a peer may close whenever it likes and idempotent
requests should be retried.
The digest is the OCI index, 8 manifests, same shape as the pin it replaces.
docker-base pins the same node tag in node/Dockerfile and bases builder-base on
this runner, so it follows once this is built.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three minor releases behind. Checksums generated by y-bin-download-next, which
verifies each one against the .sha256 the release publishes rather than trusting
the bytes it just downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Crosses 1.0, so worth naming what is in it: v1.0.1 "platforms OCI
normalization" and v1.1.0 "add push, mirror and registry-proxy, with optional
direct-to-storage upload". There is no v1.0.0 release; 0.9.2 is followed
directly by 1.0.1. Neither note lists a breaking change - no config schema
change, no removed or renamed flag - so checkit's `contain build -x
--file-output checkit-images.json --platforms-env-require` should be unaffected.
Unverified here, and the reason to watch the first builds: "platforms OCI
normalization" is the one change that touches what --platforms-env-require
reads, and the release notes do not say how.
Checksums from y-bin-download-next. contain publishes no .sha256, so these are
hashes of the downloaded artifacts rather than something cross-checked against
the release - unlike skaffold in the previous commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One patch release. Checksums from y-bin-download-next; the npm tarballs carry no
published .sha256 to cross-check against, so these are hashes of what was
downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jq moved org years ago; the download template still pointed at stedolan/jq,
which GitHub redirects, so it kept working and hid the fact that we were two
minors behind on a repo we were not really watching. 1.8.x is only published
under jqlang/jq. Asset names are unchanged (jq-macos-arm64, jq-linux-amd64 and
so on), so only the org in the URL moves.
The 1.8 line also publishes sha256sum.txt, so this adds the sha256 template
alongside the download one. y-bin-download-next then verifies each hash against
what the release published instead of hashing whatever it downloaded - the same
treatment skaffold gets, and the reason all four checksums here are stronger
evidence than the ones they replace.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch on the 3 line, staying there. Helm 4.2.4 exists and is a separate
decision, not a version bump.
Note this pin is not what the runner image ships: runner.Dockerfile installs
helm from the buildkite helm-debian apt repo instead, a documented workaround
for get.helm.sh SSL failures in GitHub Actions, and copies it in as
y-helm-<version>-bin. This pin governs the on-demand download path. The two
sources are worth reconciling; not in this commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three patches. Hashes of the downloaded artifacts: yq publishes checksums, but
in a format that needs checksums_hashes_order to parse, which is why the sha256
template is commented out in this block rather than missing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch. Hashes of the downloaded artifacts; cue publishes no per-asset .sha256
for y-bin-download-next to check against.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One buildkit minor. This is the client only; the buildkitd running in-cluster is
pinned separately, and buildkit supports a version skew between them, but if
builds start behaving oddly that pairing is the first thing to check.
Hashes of the downloaded artifacts; the release publishes no per-asset .sha256.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dead since the script it was written for stopped existing. fe5e0f8 added it in
2026-04-22 to replace kubectl-yconverge's `_find_cue_dir` bash heuristic with a
real walk of the kustomize tree; 9b60ed6 then dropped those provisioning
scripts for the y-cluster binary, and bin/kubectl-yconverge is now a symlink to
`cluster`. Nothing under ~/Yolean has referred to y-kustomize-traverse since -
not ystack, not checkit, not docker-base - and the runner image never baked it
in, so the pin has been carrying a download nobody performs.
The traversal itself is not obsolete, it moved. ccec90e in y-cluster,
"extract traverse package, rename module to y-cluster", turned this project into
that one: the walk lives in pkg/kustomize/traverse and reaches the CLI as
`y-cluster yconverge`, which aggregates CUE files reachable through kustomize
resources/components/bases. For the traversal on its own, without applying
anything, that is `y-cluster yconverge --print-deps`, which prints the
topological order. y-cluster is already pinned in this file as `cluster`.
Which is also why this is a removal and not a bump. The rename means
"kustomize-traverse latest" resolves to y-cluster v0.5.0, but that release
publishes only y-cluster_v0.5.0_* assets - no kustomize-traverse-*.tar.gz - so
raising the version here would have produced a 404 on first download. v0.1.0 is
the last release that this URL can ever resolve.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@solsson
solsson merged commit a7db143 into mainAug 31, 2026
2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@solsson
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Node.js 24.20.0 and various tool upgrades - #81

Merged
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps
Aug 31, 2026
Merged

Node.js 24.20.0 and various tool upgrades#81
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps

Conversation

@solsson

Copy link
Copy Markdown
Collaborator

No description provided.

solssonand others added 10 commits August 31, 2026 07:57
Two patch releases, and with them undici 7.28.0 -> 7.29.0 in the runtime that
serves every global fetch() in a node service. That undici release is
security-only: GHSA-4cwx-7wf7-3272 (Cache-Control parser, cross-user cache
disclosure / parse crash) plus four medium advisories in Blob H1 request
bodies, no-cache/private parsing, the retry interceptor's Content-Length and
setCookie sanitization.
checkit already overrides the *npm* undici to 7.29.0 for the first of those
(pnpm-workspace.yaml), but an override cannot reach the copy bundled in node,
which is the one behind fetch(). Measured in the images rather than inferred:
gcr.io/distroless/nodejs24-debian13:nonroot pinned since 2026-07-14
node 24.18.0, undici 7.28.0
the same tag today
node 24.20.0, undici 7.29.0
Not a fix for anything observed. rest-v1 hit UND_ERR_SOCKET "other side closed"
against kkv-userstate on 2026-08-31, and no undici release addresses that -
upstream's position is that a peer may close whenever it likes and idempotent
requests should be retried.
The digest is the OCI index, 8 manifests, same shape as the pin it replaces.
docker-base pins the same node tag in node/Dockerfile and bases builder-base on
this runner, so it follows once this is built.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three minor releases behind. Checksums generated by y-bin-download-next, which
verifies each one against the .sha256 the release publishes rather than trusting
the bytes it just downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Crosses 1.0, so worth naming what is in it: v1.0.1 "platforms OCI
normalization" and v1.1.0 "add push, mirror and registry-proxy, with optional
direct-to-storage upload". There is no v1.0.0 release; 0.9.2 is followed
directly by 1.0.1. Neither note lists a breaking change - no config schema
change, no removed or renamed flag - so checkit's `contain build -x
--file-output checkit-images.json --platforms-env-require` should be unaffected.
Unverified here, and the reason to watch the first builds: "platforms OCI
normalization" is the one change that touches what --platforms-env-require
reads, and the release notes do not say how.
Checksums from y-bin-download-next. contain publishes no .sha256, so these are
hashes of the downloaded artifacts rather than something cross-checked against
the release - unlike skaffold in the previous commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One patch release. Checksums from y-bin-download-next; the npm tarballs carry no
published .sha256 to cross-check against, so these are hashes of what was
downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jq moved org years ago; the download template still pointed at stedolan/jq,
which GitHub redirects, so it kept working and hid the fact that we were two
minors behind on a repo we were not really watching. 1.8.x is only published
under jqlang/jq. Asset names are unchanged (jq-macos-arm64, jq-linux-amd64 and
so on), so only the org in the URL moves.
The 1.8 line also publishes sha256sum.txt, so this adds the sha256 template
alongside the download one. y-bin-download-next then verifies each hash against
what the release published instead of hashing whatever it downloaded - the same
treatment skaffold gets, and the reason all four checksums here are stronger
evidence than the ones they replace.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch on the 3 line, staying there. Helm 4.2.4 exists and is a separate
decision, not a version bump.
Note this pin is not what the runner image ships: runner.Dockerfile installs
helm from the buildkite helm-debian apt repo instead, a documented workaround
for get.helm.sh SSL failures in GitHub Actions, and copies it in as
y-helm-<version>-bin. This pin governs the on-demand download path. The two
sources are worth reconciling; not in this commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three patches. Hashes of the downloaded artifacts: yq publishes checksums, but
in a format that needs checksums_hashes_order to parse, which is why the sha256
template is commented out in this block rather than missing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch. Hashes of the downloaded artifacts; cue publishes no per-asset .sha256
for y-bin-download-next to check against.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One buildkit minor. This is the client only; the buildkitd running in-cluster is
pinned separately, and buildkit supports a version skew between them, but if
builds start behaving oddly that pairing is the first thing to check.
Hashes of the downloaded artifacts; the release publishes no per-asset .sha256.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dead since the script it was written for stopped existing. fe5e0f8 added it in
2026-04-22 to replace kubectl-yconverge's `_find_cue_dir` bash heuristic with a
real walk of the kustomize tree; 9b60ed6 then dropped those provisioning
scripts for the y-cluster binary, and bin/kubectl-yconverge is now a symlink to
`cluster`. Nothing under ~/Yolean has referred to y-kustomize-traverse since -
not ystack, not checkit, not docker-base - and the runner image never baked it
in, so the pin has been carrying a download nobody performs.
The traversal itself is not obsolete, it moved. ccec90e in y-cluster,
"extract traverse package, rename module to y-cluster", turned this project into
that one: the walk lives in pkg/kustomize/traverse and reaches the CLI as
`y-cluster yconverge`, which aggregates CUE files reachable through kustomize
resources/components/bases. For the traversal on its own, without applying
anything, that is `y-cluster yconverge --print-deps`, which prints the
topological order. y-cluster is already pinned in this file as `cluster`.
Which is also why this is a removal and not a bump. The rename means
"kustomize-traverse latest" resolves to y-cluster v0.5.0, but that release
publishes only y-cluster_v0.5.0_* assets - no kustomize-traverse-*.tar.gz - so
raising the version here would have produced a 404 on first download. v0.1.0 is
the last release that this URL can ever resolve.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@solsson
solsson merged commit a7db143 into mainAug 31, 2026
2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@solsson
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Node.js 24.20.0 and various tool upgrades - #81

Merged
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps
Aug 31, 2026
Merged

Node.js 24.20.0 and various tool upgrades#81
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps

Conversation

@solsson

Copy link
Copy Markdown
Collaborator

No description provided.

solssonand others added 10 commits August 31, 2026 07:57
Two patch releases, and with them undici 7.28.0 -> 7.29.0 in the runtime that
serves every global fetch() in a node service. That undici release is
security-only: GHSA-4cwx-7wf7-3272 (Cache-Control parser, cross-user cache
disclosure / parse crash) plus four medium advisories in Blob H1 request
bodies, no-cache/private parsing, the retry interceptor's Content-Length and
setCookie sanitization.
checkit already overrides the *npm* undici to 7.29.0 for the first of those
(pnpm-workspace.yaml), but an override cannot reach the copy bundled in node,
which is the one behind fetch(). Measured in the images rather than inferred:
gcr.io/distroless/nodejs24-debian13:nonroot pinned since 2026-07-14
node 24.18.0, undici 7.28.0
the same tag today
node 24.20.0, undici 7.29.0
Not a fix for anything observed. rest-v1 hit UND_ERR_SOCKET "other side closed"
against kkv-userstate on 2026-08-31, and no undici release addresses that -
upstream's position is that a peer may close whenever it likes and idempotent
requests should be retried.
The digest is the OCI index, 8 manifests, same shape as the pin it replaces.
docker-base pins the same node tag in node/Dockerfile and bases builder-base on
this runner, so it follows once this is built.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three minor releases behind. Checksums generated by y-bin-download-next, which
verifies each one against the .sha256 the release publishes rather than trusting
the bytes it just downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Crosses 1.0, so worth naming what is in it: v1.0.1 "platforms OCI
normalization" and v1.1.0 "add push, mirror and registry-proxy, with optional
direct-to-storage upload". There is no v1.0.0 release; 0.9.2 is followed
directly by 1.0.1. Neither note lists a breaking change - no config schema
change, no removed or renamed flag - so checkit's `contain build -x
--file-output checkit-images.json --platforms-env-require` should be unaffected.
Unverified here, and the reason to watch the first builds: "platforms OCI
normalization" is the one change that touches what --platforms-env-require
reads, and the release notes do not say how.
Checksums from y-bin-download-next. contain publishes no .sha256, so these are
hashes of the downloaded artifacts rather than something cross-checked against
the release - unlike skaffold in the previous commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One patch release. Checksums from y-bin-download-next; the npm tarballs carry no
published .sha256 to cross-check against, so these are hashes of what was
downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jq moved org years ago; the download template still pointed at stedolan/jq,
which GitHub redirects, so it kept working and hid the fact that we were two
minors behind on a repo we were not really watching. 1.8.x is only published
under jqlang/jq. Asset names are unchanged (jq-macos-arm64, jq-linux-amd64 and
so on), so only the org in the URL moves.
The 1.8 line also publishes sha256sum.txt, so this adds the sha256 template
alongside the download one. y-bin-download-next then verifies each hash against
what the release published instead of hashing whatever it downloaded - the same
treatment skaffold gets, and the reason all four checksums here are stronger
evidence than the ones they replace.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch on the 3 line, staying there. Helm 4.2.4 exists and is a separate
decision, not a version bump.
Note this pin is not what the runner image ships: runner.Dockerfile installs
helm from the buildkite helm-debian apt repo instead, a documented workaround
for get.helm.sh SSL failures in GitHub Actions, and copies it in as
y-helm-<version>-bin. This pin governs the on-demand download path. The two
sources are worth reconciling; not in this commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three patches. Hashes of the downloaded artifacts: yq publishes checksums, but
in a format that needs checksums_hashes_order to parse, which is why the sha256
template is commented out in this block rather than missing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch. Hashes of the downloaded artifacts; cue publishes no per-asset .sha256
for y-bin-download-next to check against.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One buildkit minor. This is the client only; the buildkitd running in-cluster is
pinned separately, and buildkit supports a version skew between them, but if
builds start behaving oddly that pairing is the first thing to check.
Hashes of the downloaded artifacts; the release publishes no per-asset .sha256.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dead since the script it was written for stopped existing. fe5e0f8 added it in
2026-04-22 to replace kubectl-yconverge's `_find_cue_dir` bash heuristic with a
real walk of the kustomize tree; 9b60ed6 then dropped those provisioning
scripts for the y-cluster binary, and bin/kubectl-yconverge is now a symlink to
`cluster`. Nothing under ~/Yolean has referred to y-kustomize-traverse since -
not ystack, not checkit, not docker-base - and the runner image never baked it
in, so the pin has been carrying a download nobody performs.
The traversal itself is not obsolete, it moved. ccec90e in y-cluster,
"extract traverse package, rename module to y-cluster", turned this project into
that one: the walk lives in pkg/kustomize/traverse and reaches the CLI as
`y-cluster yconverge`, which aggregates CUE files reachable through kustomize
resources/components/bases. For the traversal on its own, without applying
anything, that is `y-cluster yconverge --print-deps`, which prints the
topological order. y-cluster is already pinned in this file as `cluster`.
Which is also why this is a removal and not a bump. The rename means
"kustomize-traverse latest" resolves to y-cluster v0.5.0, but that release
publishes only y-cluster_v0.5.0_* assets - no kustomize-traverse-*.tar.gz - so
raising the version here would have produced a 404 on first download. v0.1.0 is
the last release that this URL can ever resolve.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@solsson
solsson merged commit a7db143 into mainAug 31, 2026
2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@solsson
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Node.js 24.20.0 and various tool upgrades - #81

Merged
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps
Aug 31, 2026
Merged

Node.js 24.20.0 and various tool upgrades#81
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps

Conversation

@solsson

Copy link
Copy Markdown
Collaborator

No description provided.

solssonand others added 10 commits August 31, 2026 07:57
Two patch releases, and with them undici 7.28.0 -> 7.29.0 in the runtime that
serves every global fetch() in a node service. That undici release is
security-only: GHSA-4cwx-7wf7-3272 (Cache-Control parser, cross-user cache
disclosure / parse crash) plus four medium advisories in Blob H1 request
bodies, no-cache/private parsing, the retry interceptor's Content-Length and
setCookie sanitization.
checkit already overrides the *npm* undici to 7.29.0 for the first of those
(pnpm-workspace.yaml), but an override cannot reach the copy bundled in node,
which is the one behind fetch(). Measured in the images rather than inferred:
gcr.io/distroless/nodejs24-debian13:nonroot pinned since 2026-07-14
node 24.18.0, undici 7.28.0
the same tag today
node 24.20.0, undici 7.29.0
Not a fix for anything observed. rest-v1 hit UND_ERR_SOCKET "other side closed"
against kkv-userstate on 2026-08-31, and no undici release addresses that -
upstream's position is that a peer may close whenever it likes and idempotent
requests should be retried.
The digest is the OCI index, 8 manifests, same shape as the pin it replaces.
docker-base pins the same node tag in node/Dockerfile and bases builder-base on
this runner, so it follows once this is built.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three minor releases behind. Checksums generated by y-bin-download-next, which
verifies each one against the .sha256 the release publishes rather than trusting
the bytes it just downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Crosses 1.0, so worth naming what is in it: v1.0.1 "platforms OCI
normalization" and v1.1.0 "add push, mirror and registry-proxy, with optional
direct-to-storage upload". There is no v1.0.0 release; 0.9.2 is followed
directly by 1.0.1. Neither note lists a breaking change - no config schema
change, no removed or renamed flag - so checkit's `contain build -x
--file-output checkit-images.json --platforms-env-require` should be unaffected.
Unverified here, and the reason to watch the first builds: "platforms OCI
normalization" is the one change that touches what --platforms-env-require
reads, and the release notes do not say how.
Checksums from y-bin-download-next. contain publishes no .sha256, so these are
hashes of the downloaded artifacts rather than something cross-checked against
the release - unlike skaffold in the previous commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One patch release. Checksums from y-bin-download-next; the npm tarballs carry no
published .sha256 to cross-check against, so these are hashes of what was
downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jq moved org years ago; the download template still pointed at stedolan/jq,
which GitHub redirects, so it kept working and hid the fact that we were two
minors behind on a repo we were not really watching. 1.8.x is only published
under jqlang/jq. Asset names are unchanged (jq-macos-arm64, jq-linux-amd64 and
so on), so only the org in the URL moves.
The 1.8 line also publishes sha256sum.txt, so this adds the sha256 template
alongside the download one. y-bin-download-next then verifies each hash against
what the release published instead of hashing whatever it downloaded - the same
treatment skaffold gets, and the reason all four checksums here are stronger
evidence than the ones they replace.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch on the 3 line, staying there. Helm 4.2.4 exists and is a separate
decision, not a version bump.
Note this pin is not what the runner image ships: runner.Dockerfile installs
helm from the buildkite helm-debian apt repo instead, a documented workaround
for get.helm.sh SSL failures in GitHub Actions, and copies it in as
y-helm-<version>-bin. This pin governs the on-demand download path. The two
sources are worth reconciling; not in this commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three patches. Hashes of the downloaded artifacts: yq publishes checksums, but
in a format that needs checksums_hashes_order to parse, which is why the sha256
template is commented out in this block rather than missing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch. Hashes of the downloaded artifacts; cue publishes no per-asset .sha256
for y-bin-download-next to check against.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One buildkit minor. This is the client only; the buildkitd running in-cluster is
pinned separately, and buildkit supports a version skew between them, but if
builds start behaving oddly that pairing is the first thing to check.
Hashes of the downloaded artifacts; the release publishes no per-asset .sha256.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dead since the script it was written for stopped existing. fe5e0f8 added it in
2026-04-22 to replace kubectl-yconverge's `_find_cue_dir` bash heuristic with a
real walk of the kustomize tree; 9b60ed6 then dropped those provisioning
scripts for the y-cluster binary, and bin/kubectl-yconverge is now a symlink to
`cluster`. Nothing under ~/Yolean has referred to y-kustomize-traverse since -
not ystack, not checkit, not docker-base - and the runner image never baked it
in, so the pin has been carrying a download nobody performs.
The traversal itself is not obsolete, it moved. ccec90e in y-cluster,
"extract traverse package, rename module to y-cluster", turned this project into
that one: the walk lives in pkg/kustomize/traverse and reaches the CLI as
`y-cluster yconverge`, which aggregates CUE files reachable through kustomize
resources/components/bases. For the traversal on its own, without applying
anything, that is `y-cluster yconverge --print-deps`, which prints the
topological order. y-cluster is already pinned in this file as `cluster`.
Which is also why this is a removal and not a bump. The rename means
"kustomize-traverse latest" resolves to y-cluster v0.5.0, but that release
publishes only y-cluster_v0.5.0_* assets - no kustomize-traverse-*.tar.gz - so
raising the version here would have produced a 404 on first download. v0.1.0 is
the last release that this URL can ever resolve.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@solsson
solsson merged commit a7db143 into mainAug 31, 2026
2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@solsson
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Node.js 24.20.0 and various tool upgrades - #81

Merged
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps
Aug 31, 2026
Merged

Node.js 24.20.0 and various tool upgrades#81
solsson merged 10 commits into
mainfrom
runner-node-and-tool-bumps

Conversation

@solsson

Copy link
Copy Markdown
Collaborator

No description provided.

solssonand others added 10 commits August 31, 2026 07:57
Two patch releases, and with them undici 7.28.0 -> 7.29.0 in the runtime that
serves every global fetch() in a node service. That undici release is
security-only: GHSA-4cwx-7wf7-3272 (Cache-Control parser, cross-user cache
disclosure / parse crash) plus four medium advisories in Blob H1 request
bodies, no-cache/private parsing, the retry interceptor's Content-Length and
setCookie sanitization.
checkit already overrides the *npm* undici to 7.29.0 for the first of those
(pnpm-workspace.yaml), but an override cannot reach the copy bundled in node,
which is the one behind fetch(). Measured in the images rather than inferred:
gcr.io/distroless/nodejs24-debian13:nonroot pinned since 2026-07-14
node 24.18.0, undici 7.28.0
the same tag today
node 24.20.0, undici 7.29.0
Not a fix for anything observed. rest-v1 hit UND_ERR_SOCKET "other side closed"
against kkv-userstate on 2026-08-31, and no undici release addresses that -
upstream's position is that a peer may close whenever it likes and idempotent
requests should be retried.
The digest is the OCI index, 8 manifests, same shape as the pin it replaces.
docker-base pins the same node tag in node/Dockerfile and bases builder-base on
this runner, so it follows once this is built.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three minor releases behind. Checksums generated by y-bin-download-next, which
verifies each one against the .sha256 the release publishes rather than trusting
the bytes it just downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Crosses 1.0, so worth naming what is in it: v1.0.1 "platforms OCI
normalization" and v1.1.0 "add push, mirror and registry-proxy, with optional
direct-to-storage upload". There is no v1.0.0 release; 0.9.2 is followed
directly by 1.0.1. Neither note lists a breaking change - no config schema
change, no removed or renamed flag - so checkit's `contain build -x
--file-output checkit-images.json --platforms-env-require` should be unaffected.
Unverified here, and the reason to watch the first builds: "platforms OCI
normalization" is the one change that touches what --platforms-env-require
reads, and the release notes do not say how.
Checksums from y-bin-download-next. contain publishes no .sha256, so these are
hashes of the downloaded artifacts rather than something cross-checked against
the release - unlike skaffold in the previous commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One patch release. Checksums from y-bin-download-next; the npm tarballs carry no
published .sha256 to cross-check against, so these are hashes of what was
downloaded.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jq moved org years ago; the download template still pointed at stedolan/jq,
which GitHub redirects, so it kept working and hid the fact that we were two
minors behind on a repo we were not really watching. 1.8.x is only published
under jqlang/jq. Asset names are unchanged (jq-macos-arm64, jq-linux-amd64 and
so on), so only the org in the URL moves.
The 1.8 line also publishes sha256sum.txt, so this adds the sha256 template
alongside the download one. y-bin-download-next then verifies each hash against
what the release published instead of hashing whatever it downloaded - the same
treatment skaffold gets, and the reason all four checksums here are stronger
evidence than the ones they replace.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch on the 3 line, staying there. Helm 4.2.4 exists and is a separate
decision, not a version bump.
Note this pin is not what the runner image ships: runner.Dockerfile installs
helm from the buildkite helm-debian apt repo instead, a documented workaround
for get.helm.sh SSL failures in GitHub Actions, and copies it in as
y-helm-<version>-bin. This pin governs the on-demand download path. The two
sources are worth reconciling; not in this commit.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three patches. Hashes of the downloaded artifacts: yq publishes checksums, but
in a format that needs checksums_hashes_order to parse, which is why the sha256
template is commented out in this block rather than missing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch. Hashes of the downloaded artifacts; cue publishes no per-asset .sha256
for y-bin-download-next to check against.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One buildkit minor. This is the client only; the buildkitd running in-cluster is
pinned separately, and buildkit supports a version skew between them, but if
builds start behaving oddly that pairing is the first thing to check.
Hashes of the downloaded artifacts; the release publishes no per-asset .sha256.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dead since the script it was written for stopped existing. fe5e0f8 added it in
2026-04-22 to replace kubectl-yconverge's `_find_cue_dir` bash heuristic with a
real walk of the kustomize tree; 9b60ed6 then dropped those provisioning
scripts for the y-cluster binary, and bin/kubectl-yconverge is now a symlink to
`cluster`. Nothing under ~/Yolean has referred to y-kustomize-traverse since -
not ystack, not checkit, not docker-base - and the runner image never baked it
in, so the pin has been carrying a download nobody performs.
The traversal itself is not obsolete, it moved. ccec90e in y-cluster,
"extract traverse package, rename module to y-cluster", turned this project into
that one: the walk lives in pkg/kustomize/traverse and reaches the CLI as
`y-cluster yconverge`, which aggregates CUE files reachable through kustomize
resources/components/bases. For the traversal on its own, without applying
anything, that is `y-cluster yconverge --print-deps`, which prints the
topological order. y-cluster is already pinned in this file as `cluster`.
Which is also why this is a removal and not a bump. The rename means
"kustomize-traverse latest" resolves to y-cluster v0.5.0, but that release
publishes only y-cluster_v0.5.0_* assets - no kustomize-traverse-*.tar.gz - so
raising the version here would have produced a 404 on first download. v0.1.0 is
the last release that this URL can ever resolve.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@solsson
solsson merged commit a7db143 into mainAug 31, 2026
2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@solsson