chore: downgrade bun to 1.2.12 - #38
Conversation
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 57 minutes and 13 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
WalkthroughThis PR systematically downgrades the Bun runtime version from 1.3.11 to 1.2.12 across GitHub Actions workflows, the Dockerfile, and Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
Dockerfile (1)
1-25:⚠️ Potential issue | 🟠 MajorRun the production container as a non-root user.
The image still executes as root (no
USERset), which is a security hardening gap for runtime compromise scenarios.Suggested hardening patch
FROM base AS prod ENV NODE_ENV=production \ PORT=3000 \ HOSTNAME=0.0.0.0 \ FFMPEG_PATH=/usr/local/bin/ffmpeg +RUN addgroup --system app && adduser --system --ingroup app app COPY --from=mwader/static-ffmpeg:7.1.1 /ffmpeg /usr/local/bin/ -COPY --from=build /app/packages/server/dist/server/app.js /app/app.js -COPY --from=install /app/node_modules/ /app/node_modules/ +COPY --chown=app:app --from=build /app/packages/server/dist/server/app.js /app/app.js +COPY --chown=app:app --from=install /app/node_modules/ /app/node_modules/ +USER app EXPOSE 3000 CMD ["bun", "app.js"]🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@Dockerfile` around lines 1 - 25, The Dockerfile runs the prod image as root; add steps in the prod stage to create a non-root user/group, chown the application directories and any copied binaries (e.g., /app and /usr/local/bin/ffmpeg), and switch to that user before EXPOSE/CMD (i.e., update the "prod" stage after COPY --from=... lines to create/own files and set USER to the new non-root account so bun runs unprivileged). Ensure the new user has a home and limited permissions and that file ownership matches the user so bun can read/write as needed.
🧹 Nitpick comments (1)
packages/client/package.json (1)
40-40: Pin@types/bunexactly to avoid silent drift from runtime version.Using
^1.2.12can resolve to newer 1.x typings while runtime is pinned to 1.2.12, which weakens the downgrade consistency goal.Suggested change
- "@types/bun": "^1.2.12", + "@types/bun": "1.2.12",🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@packages/client/package.json` at line 40, The dependency entry "@types/bun" currently uses a caret range "^1.2.12" which allows silent upgrades; update the packages/client package.json dependency for "@types/bun" to an exact version "1.2.12" (remove the caret) so the typings are pinned to the runtime version, then run your install/lockfile update and verify the lockfile reflects the exact 1.2.12 version.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@Dockerfile`:
- Around line 1-25: The Dockerfile runs the prod image as root; add steps in the
prod stage to create a non-root user/group, chown the application directories
and any copied binaries (e.g., /app and /usr/local/bin/ffmpeg), and switch to
that user before EXPOSE/CMD (i.e., update the "prod" stage after COPY --from=...
lines to create/own files and set USER to the new non-root account so bun runs
unprivileged). Ensure the new user has a home and limited permissions and that
file ownership matches the user so bun can read/write as needed.
---
Nitpick comments:
In `@packages/client/package.json`:
- Line 40: The dependency entry "@types/bun" currently uses a caret range
"^1.2.12" which allows silent upgrades; update the packages/client package.json
dependency for "@types/bun" to an exact version "1.2.12" (remove the caret) so
the typings are pinned to the runtime version, then run your install/lockfile
update and verify the lockfile reflects the exact 1.2.12 version.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: cbdd955e-7af0-403c-9f90-8ae1665f55ec
⛔ Files ignored due to path filters (1)
bun.lockis excluded by!**/*.lock
📒 Files selected for processing (6)
.github/workflows/build-push.yaml.github/workflows/test-build.yamlDockerfilepackages/client/package.jsonpackages/server/package.jsonpackages/typebox/package.json
Updates bun from 1.3.11 to 1.3.12 across Dockerfile, workflows, and package dependencies.
e5acdd6 to
cabe8d5
Compare
Updates bun from 1.3.11 to 1.2.12 across Dockerfile, workflows, and package dependencies.
Summary by CodeRabbit