Skip to content

chore: downgrade bun to 1.2.12 - #38

Merged
sv2dev merged 1 commit into
mainfrom
chore/update-bun
Apr 14, 2026
Merged

sv2dev merged 1 commit into
mainfrom
chore/update-bun

Conversation

@sv2dev

@sv2dev sv2dev commented Apr 14, 2026 •

Copy link
Copy Markdown
Owner

Updates bun from 1.3.11 to 1.2.12 across Dockerfile, workflows, and package dependencies.

Summary by CodeRabbit

  • Chores
    • Downgraded Bun runtime version from 1.3.11 to 1.2.12 in CI/CD workflows and Docker configuration
    • Updated corresponding type definition dependencies across packages

@coderabbitai

coderabbitai Bot commented Apr 14, 2026 •

Copy link
Copy Markdown

Warning

Rate limit exceeded

@sv2dev has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 57 minutes and 13 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 57 minutes and 13 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 26ffa69e-7617-4afc-915b-4d95093939df

📥 Commits

Reviewing files that changed from the base of the PR and between e5acdd6 and cabe8d5.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock
📒 Files selected for processing (6)
  • .github/workflows/build-push.yaml
  • .github/workflows/test-build.yaml
  • Dockerfile
  • packages/client/package.json
  • packages/server/package.json
  • packages/typebox/package.json

Walkthrough

This PR systematically downgrades the Bun runtime version from 1.3.11 to 1.2.12 across GitHub Actions workflows, the Dockerfile, and @types/bun development dependencies in multiple package.json files.

Changes

Cohort / File(s) Summary
GitHub Actions Workflows
.github/workflows/build-push.yaml, .github/workflows/test-build.yaml
Downgraded Bun runtime version from 1.3.11 to 1.2.12 in the publish job and test job execution environments.
Docker Configuration
Dockerfile
Updated base image from oven/bun:1.3.11-slim to oven/bun:1.2.12-slim.
Package Dependencies
packages/client/package.json, packages/server/package.json, packages/typebox/package.json
Downgraded @types/bun devDependency from ^1.3.11 to ^1.2.12 across all packages.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • build: upgrade bun to 1.3.11 #33: Makes the inverse change, upgrading the same Bun version pins and @types/bun dependencies from 1.2.12 back to 1.3.11 across identical files.

Poem

🐰 Hop backwards through the version spree,
From 1.3 to 1.2, oh what we see!
A simpler Bun for cleaner builds,
Downgrade dance through CI's fields! 🎯

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'chore: downgrade bun to 1.2.12' directly and accurately summarizes the main change—downgrading the Bun runtime version across multiple configuration files and dependencies.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/update-bun

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
Dockerfile (1)

1-25: ⚠️ Potential issue | 🟠 Major

Run the production container as a non-root user.

The image still executes as root (no USER set), which is a security hardening gap for runtime compromise scenarios.

Suggested hardening patch
 FROM base AS prod
 ENV NODE_ENV=production \
     PORT=3000 \
     HOSTNAME=0.0.0.0 \
     FFMPEG_PATH=/usr/local/bin/ffmpeg
+RUN addgroup --system app && adduser --system --ingroup app app
 COPY --from=mwader/static-ffmpeg:7.1.1 /ffmpeg /usr/local/bin/
-COPY --from=build /app/packages/server/dist/server/app.js /app/app.js
-COPY --from=install /app/node_modules/ /app/node_modules/
+COPY --chown=app:app --from=build /app/packages/server/dist/server/app.js /app/app.js
+COPY --chown=app:app --from=install /app/node_modules/ /app/node_modules/
+USER app
 EXPOSE 3000
 CMD ["bun", "app.js"]
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@Dockerfile` around lines 1 - 25, The Dockerfile runs the prod image as root;
add steps in the prod stage to create a non-root user/group, chown the
application directories and any copied binaries (e.g., /app and
/usr/local/bin/ffmpeg), and switch to that user before EXPOSE/CMD (i.e., update
the "prod" stage after COPY --from=... lines to create/own files and set USER to
the new non-root account so bun runs unprivileged). Ensure the new user has a
home and limited permissions and that file ownership matches the user so bun can
read/write as needed.
🧹 Nitpick comments (1)
packages/client/package.json (1)

40-40: Pin @types/bun exactly to avoid silent drift from runtime version.

Using ^1.2.12 can resolve to newer 1.x typings while runtime is pinned to 1.2.12, which weakens the downgrade consistency goal.

Suggested change
-    "@types/bun": "^1.2.12",
+    "@types/bun": "1.2.12",
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@packages/client/package.json` at line 40, The dependency entry "@types/bun"
currently uses a caret range "^1.2.12" which allows silent upgrades; update the
packages/client package.json dependency for "@types/bun" to an exact version
"1.2.12" (remove the caret) so the typings are pinned to the runtime version,
then run your install/lockfile update and verify the lockfile reflects the exact
1.2.12 version.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Outside diff comments:
In `@Dockerfile`:
- Around line 1-25: The Dockerfile runs the prod image as root; add steps in the
prod stage to create a non-root user/group, chown the application directories
and any copied binaries (e.g., /app and /usr/local/bin/ffmpeg), and switch to
that user before EXPOSE/CMD (i.e., update the "prod" stage after COPY --from=...
lines to create/own files and set USER to the new non-root account so bun runs
unprivileged). Ensure the new user has a home and limited permissions and that
file ownership matches the user so bun can read/write as needed.

---

Nitpick comments:
In `@packages/client/package.json`:
- Line 40: The dependency entry "@types/bun" currently uses a caret range
"^1.2.12" which allows silent upgrades; update the packages/client package.json
dependency for "@types/bun" to an exact version "1.2.12" (remove the caret) so
the typings are pinned to the runtime version, then run your install/lockfile
update and verify the lockfile reflects the exact 1.2.12 version.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: cbdd955e-7af0-403c-9f90-8ae1665f55ec

📥 Commits

Reviewing files that changed from the base of the PR and between a9ec070 and e5acdd6.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock
📒 Files selected for processing (6)
  • .github/workflows/build-push.yaml
  • .github/workflows/test-build.yaml
  • Dockerfile
  • packages/client/package.json
  • packages/server/package.json
  • packages/typebox/package.json

Updates bun from 1.3.11 to 1.3.12 across Dockerfile, workflows, and package dependencies.
@sv2dev
sv2dev force-pushed the chore/update-bun branch from e5acdd6 to cabe8d5 Compare April 14, 2026 17:53
@sv2dev
sv2dev merged commit 3f20f7f into main Apr 14, 2026
2 checks passed
@sv2dev
sv2dev deleted the chore/update-bun branch April 14, 2026 17:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant