Uh oh!
There was an error while loading. Please reload this page.
Node.js 24.20.0 and various tool upgrades - #81
Merged
Conversation
Two patch releases, and with them undici 7.28.0 -> 7.29.0 in the runtime that serves every global fetch() in a node service. That undici release is security-only: GHSA-4cwx-7wf7-3272 (Cache-Control parser, cross-user cache disclosure / parse crash) plus four medium advisories in Blob H1 request bodies, no-cache/private parsing, the retry interceptor's Content-Length and setCookie sanitization. checkit already overrides the *npm* undici to 7.29.0 for the first of those (pnpm-workspace.yaml), but an override cannot reach the copy bundled in node, which is the one behind fetch(). Measured in the images rather than inferred: gcr.io/distroless/nodejs24-debian13:nonroot pinned since 2026-07-14 node 24.18.0, undici 7.28.0 the same tag today node 24.20.0, undici 7.29.0 Not a fix for anything observed. rest-v1 hit UND_ERR_SOCKET "other side closed" against kkv-userstate on 2026-08-31, and no undici release addresses that - upstream's position is that a peer may close whenever it likes and idempotent requests should be retried. The digest is the OCI index, 8 manifests, same shape as the pin it replaces. docker-base pins the same node tag in node/Dockerfile and bases builder-base on this runner, so it follows once this is built. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three minor releases behind. Checksums generated by y-bin-download-next, which verifies each one against the .sha256 the release publishes rather than trusting the bytes it just downloaded. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Crosses 1.0, so worth naming what is in it: v1.0.1 "platforms OCI normalization" and v1.1.0 "add push, mirror and registry-proxy, with optional direct-to-storage upload". There is no v1.0.0 release; 0.9.2 is followed directly by 1.0.1. Neither note lists a breaking change - no config schema change, no removed or renamed flag - so checkit's `contain build -x --file-output checkit-images.json --platforms-env-require` should be unaffected. Unverified here, and the reason to watch the first builds: "platforms OCI normalization" is the one change that touches what --platforms-env-require reads, and the release notes do not say how. Checksums from y-bin-download-next. contain publishes no .sha256, so these are hashes of the downloaded artifacts rather than something cross-checked against the release - unlike skaffold in the previous commit. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One patch release. Checksums from y-bin-download-next; the npm tarballs carry no published .sha256 to cross-check against, so these are hashes of what was downloaded. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jq moved org years ago; the download template still pointed at stedolan/jq, which GitHub redirects, so it kept working and hid the fact that we were two minors behind on a repo we were not really watching. 1.8.x is only published under jqlang/jq. Asset names are unchanged (jq-macos-arm64, jq-linux-amd64 and so on), so only the org in the URL moves. The 1.8 line also publishes sha256sum.txt, so this adds the sha256 template alongside the download one. y-bin-download-next then verifies each hash against what the release published instead of hashing whatever it downloaded - the same treatment skaffold gets, and the reason all four checksums here are stronger evidence than the ones they replace. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch on the 3 line, staying there. Helm 4.2.4 exists and is a separate decision, not a version bump. Note this pin is not what the runner image ships: runner.Dockerfile installs helm from the buildkite helm-debian apt repo instead, a documented workaround for get.helm.sh SSL failures in GitHub Actions, and copies it in as y-helm-<version>-bin. This pin governs the on-demand download path. The two sources are worth reconciling; not in this commit. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three patches. Hashes of the downloaded artifacts: yq publishes checksums, but in a format that needs checksums_hashes_order to parse, which is why the sha256 template is commented out in this block rather than missing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Patch. Hashes of the downloaded artifacts; cue publishes no per-asset .sha256 for y-bin-download-next to check against. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One buildkit minor. This is the client only; the buildkitd running in-cluster is pinned separately, and buildkit supports a version skew between them, but if builds start behaving oddly that pairing is the first thing to check. Hashes of the downloaded artifacts; the release publishes no per-asset .sha256. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Dead since the script it was written for stopped existing. fe5e0f8 added it in 2026-04-22 to replace kubectl-yconverge's `_find_cue_dir` bash heuristic with a real walk of the kustomize tree; 9b60ed6 then dropped those provisioning scripts for the y-cluster binary, and bin/kubectl-yconverge is now a symlink to `cluster`. Nothing under ~/Yolean has referred to y-kustomize-traverse since - not ystack, not checkit, not docker-base - and the runner image never baked it in, so the pin has been carrying a download nobody performs. The traversal itself is not obsolete, it moved. ccec90e in y-cluster, "extract traverse package, rename module to y-cluster", turned this project into that one: the walk lives in pkg/kustomize/traverse and reaches the CLI as `y-cluster yconverge`, which aggregates CUE files reachable through kustomize resources/components/bases. For the traversal on its own, without applying anything, that is `y-cluster yconverge --print-deps`, which prints the topological order. y-cluster is already pinned in this file as `cluster`. Which is also why this is a removal and not a bump. The rename means "kustomize-traverse latest" resolves to y-cluster v0.5.0, but that release publishes only y-cluster_v0.5.0_* assets - no kustomize-traverse-*.tar.gz - so raising the version here would have produced a 404 on first download. v0.1.0 is the last release that this URL can ever resolve. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Uh oh!
There was an error while loading. Please reload this page.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.