Skip to content

chore(deps): bump the production group across 1 directory with 3 updates - #369

Merged
aliasunder merged 1 commit into
mainfrom
dependabot/npm_and_yarn/production-5a092cb738
Jul 24, 2026
Merged

chore(deps): bump the production group across 1 directory with 3 updates#369
aliasunder merged 1 commit into
mainfrom
dependabot/npm_and_yarn/production-5a092cb738

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the production group with 3 updates in the / directory: better-sqlite3, @napi-rs/canvas and unpdf.

Updates better-sqlite3 from 12.11.1 to 13.0.1

Release notes

Sourced from better-sqlite3's releases.

v13.0.1

Full Changelog: WiseLibs/better-sqlite3@v13.0.0...v13.0.1

Fixed a regression in parameter binding where it would be overly strict and reject plain objects from other realms (e.g., in jest tests).

v13.0.0

Version 13.0.0 marks a major milestone, as it's the first version of better-sqlite3 to run on the N-API. This means prebuilt binaries should theoretically work across different versions of Node.js and Electron, and perhaps even other runtimes like Bun. As a result, we've removed the deprecated prebuild-install dependency, and now prebuilt binaries are published directly with the better-sqlite3 code itself. If your platform/architecture doesn't have a prebuilt binary, it should compile during install as before.

What's Changed

New Contributors

Full Changelog: WiseLibs/better-sqlite3@v12.12.0...v13.0.0

v12.12.0

What's Changed

[!WARNING]

BREAKING: Starting with Electron v43, binary assets will require glibc 2.41 or higher on Linux hosts.

Full Changelog: WiseLibs/better-sqlite3@v12.11.2...v12.12.0

v12.11.2

What's Changed

Full Changelog: WiseLibs/better-sqlite3@v12.11.1...v12.11.2

Commits
Install script changes

This version modifies install script that runs during installation. Review the package contents before updating.


Updates @napi-rs/canvas from 0.1.100 to 1.0.2

Release notes

Sourced from @​napi-rs/canvas's releases.

v1.0.2

What's Changed

Full Changelog: Brooooooklyn/canvas@v1.0.1...v1.0.2

v1.0.1

What's Changed

Full Changelog: Brooooooklyn/canvas@v1.0.0...v1.0.1

v1.0.0

What's Changed

We have achieved ~11m/week downloads, and the API is stable, so we have decided to release version 1.0 at this time. There are no breaking changes; it's safe for everyone to upgrade.

Full Changelog: Brooooooklyn/canvas@v0.1.100...v1.0.0

Changelog

Sourced from @​napi-rs/canvas's changelog.

1.0.2 (2026-06-30)

Features

1.0.1 (2026-06-24)

Bug Fixes

  • link aarch64-pc-windows-msvc against static CRT (#1276) (8483662)
  • missing icudtl.dat in win32-arm64 package (#1278) (e1a75d1)

1.0.0 (2026-05-04)

Commits

Updates unpdf from 1.6.2 to 1.7.0

Release notes

Sourced from unpdf's releases.

v1.7.0

🐞 Bug Fixes

🏎 Performance

View changes on GitHub
Commits
  • 5125d67 chore: release v1.7.0
  • 53d78fa docs: hardening guidance for untrusted PDFs (#61)
  • 95ebf64 perf: encode PNG bytes directly in renderPageAsImage (#60)
  • ed9ac1d fix: destroy internally created document proxies and canvas resources (#57)
  • a49be35 fix: preserve line breaks in extractText with mergePages (#58)
  • 6552a9e docs: collapse renderPageAsImage overloads into a single signature
  • f5406c2 fix: resolve @napi-rs/canvas in the bundled PDF.js canvas factory (#54)
  • 10e6d78 fix: add .js extension to relative imports in .d.mts & .d.cts files (#56)
  • 3789c3e fix: add cMapUrl for CJK font support in Node.js (#52)
  • ab8e04c ci: drop redundant NPM_TOKEN (publishing via OIDC)
  • Additional commits viewable in compare view

@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 24, 2026
@dependabot
dependabotBot requested a review from aliasunder as a code ownerJuly 24, 2026 14:34
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 24, 2026
@socket-security

socket-securityBot commented Jul 24, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatedunpdf@​1.6.2 ⏵ 1.7.0100+110010091+4100
Addedbetter-sqlite3@​13.0.19910010092100
Updated@​napi-rs/​canvas@​0.1.100 ⏵ 1.0.298100100+195+2100

View full report

@dependabotdependabotBot changed the title chore(deps): bump the production group with 3 updateschore(deps): bump the production group across 1 directory with 3 updatesJul 24, 2026
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/production-5a092cb738 branch from 57c445f to 383ef02CompareJuly 24, 2026 15:24
Bumps the production group with 3 updates in the / directory: [better-sqlite3](https://github.com/WiseLibs/better-sqlite3), [@napi-rs/canvas](https://github.com/Brooooooklyn/canvas) and [unpdf](https://github.com/unjs/unpdf).
Updates `better-sqlite3` from 12.11.1 to 13.0.1
- [Release notes](https://github.com/WiseLibs/better-sqlite3/releases)
- [Commits](WiseLibs/better-sqlite3@v12.11.1...v13.0.1)
Updates `@napi-rs/canvas` from 0.1.100 to 1.0.2
- [Release notes](https://github.com/Brooooooklyn/canvas/releases)
- [Changelog](https://github.com/Brooooooklyn/canvas/blob/main/CHANGELOG.md)
- [Commits](Brooooooklyn/canvas@v0.1.100...v1.0.2)
Updates `unpdf` from 1.6.2 to 1.7.0
- [Release notes](https://github.com/unjs/unpdf/releases)
- [Commits](unjs/unpdf@v1.6.2...v1.7.0)
---
updated-dependencies:
- dependency-name: "@napi-rs/canvas"
dependency-version: 1.0.2
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: production
- dependency-name: better-sqlite3
dependency-version: 13.0.1
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: production
- dependency-name: unpdf
dependency-version: 1.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/production-5a092cb738 branch from 383ef02 to da74405CompareJuly 24, 2026 15:27
@aliasunder
aliasunder merged commit 6d41452 into mainJul 24, 2026
12 checks passed
@aliasunder
aliasunder deleted the dependabot/npm_and_yarn/production-5a092cb738 branch July 24, 2026 17:55
aliasunder added a commit that referenced this pull request Jul 30, 2026
…ings per-arch at build time (#384)
## Problem
Every **arm64** image since **v0.33.0 (July 25)** crash-loops at startup
— all Apple Silicon local-mode users are affected:
```
/lib/aarch64-linux-gnu/libm.so.6: version 'GLIBC_2.38' not found
(required by /app/node_modules/better-sqlite3/prebuilds/linux-arm64.node)
```
better-sqlite3 v13 (Dependabot #369) bundles its prebuilds in the npm
tarball, and the **linux-arm64 prebuild requires glibc >= 2.38** while
the bookworm base ships **2.36**. amd64 was unaffected only because its
prebuild's glibc floor happens to fit — which is why prod (Lightsail,
amd64) never surfaced it and no CI check caught it: nothing ever
*executes* the arm64 artifact.
## Why the existing defense failed
The deps stage ran `npm ci --ignore-scripts && npm rebuild
better-sqlite3 onnxruntime-node` precisely to compile bindings against
the image's libc. Two independent failures made it dead weight:
1. **npm's allow-scripts gating silently no-ops `npm rebuild`** — it
prints a warning, reports "rebuilt dependencies successfully", and exits
0 without building anything. Reproduced in a clean container at the
exact pinned base digest.
2. **v13 tarballs no longer produce a working binding from source** —
even with scripts approved and build tools present, the compile
completes without linking a `.node` (upstream moved to bundled
prebuilds; 13.0.2 sets `gypfile: false`, making source builds a
permanent no-op).
Both shipped image arches contain **no compiled binding at all** — they
run on bundled prebuilds, so amd64 is also one upstream
prebuild-toolchain bump away from the same crash.
## Fix
- **Base image → `node:24-trixie-slim`** (glibc 2.41 ≥ 2.38),
digest-pinned as before. Aligns with upstream's prebuild-only direction
instead of fighting it.
- **Replace the dead rebuild with an executed assertion**: the deps
stage `RUN`s `new Database(':memory:')` + `require('onnxruntime-node')`.
Release builds are `linux/amd64,linux/arm64`, so this executes on
**both** architectures (arm64 under QEMU) — a glibc/arch mismatch now
**fails the build on the affected arch** instead of shipping a
crash-looping image. This makes per-arch validation a hard release gate.
- Dropped the now-unused `python3 make g++` from the deps stage (the
build stage keeps its own copy).
- Docs lockstep: AGENTS.md + ARCHITECTURE.md base-image references
updated with the glibc-floor rationale.
## Validation
- **arm64 local target**: built with the assertion passing, booted via
the CLI against a scaffolded `.env` — healthz ok, authenticated MCP
`initialize` returns serverInfo, index rebuild + **embedding pass
complete** (both native bindings exercised for real).
- **amd64 deps stage**: built under `--platform linux/amd64` emulation —
assertion passes, proving the cross-arch gate works exactly as CI will
run it.
- **remote target**: builds cleanly on trixie (s6-overlay static
binaries, obsidian-headless npm ci, UID-1000 user swap all unaffected).
- Regression window confirmed by probing released images: `0.32.0`
(better-sqlite3 12.x) opens a database on arm64; `0.33.2` and `:latest`
do not. Note: bare `require('better-sqlite3')` passes on broken images —
v13 defers the native load — so the assertion opens a real database.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@aliasunder