fix: bump pinned forgejo-workflows renovate.yml to Node 24 fix #23

Merged
james merged 1 commit from fix/renovate-node-version-pin into main 2026-09-19 14:31:59 +00:00
Owner

[email protected] requires Node ^24.11.0 (uses RegExp.escape, a Node 24+ builtin). The reusable workflow this repo calls was pinned at 280a4499, which ran the job on Node 22 -- every scheduled run crashed on an unhandled rejection loading Renovate's bazel manager, before it ever scanned a dependency. Because the rejection was unhandled rather than a caught fatal error, npx still exited 0, so every run showed as success in Actions while doing nothing: no Renovate PRs or Dependency Dashboard issue have ever been created since Renovate was added in #12.

Fix merged upstream in colibrisec/forgejo-workflows (Node 22 -> 24). This bumps the pin here to 95bdd86, the merged commit.

[email protected] requires Node ^24.11.0 (uses `RegExp.escape`, a Node 24+ builtin). The reusable workflow this repo calls was pinned at `280a4499`, which ran the job on Node 22 -- every scheduled run crashed on an unhandled rejection loading Renovate's bazel manager, before it ever scanned a dependency. Because the rejection was unhandled rather than a caught fatal error, `npx` still exited 0, so every run showed as `success` in Actions while doing nothing: no Renovate PRs or Dependency Dashboard issue have ever been created since Renovate was added in #12. Fix merged upstream in `colibrisec/forgejo-workflows` (Node 22 -> 24). This bumps the pin here to `95bdd86`, the merged commit.
fix: bump pinned forgejo-workflows renovate.yml to Node 24 fix
All checks were successful
security-scan / security-scan (pull_request) Successful in 1m17s
test / web (pull_request) Successful in 1m6s
test / coverage-badge (pull_request) Has been skipped
codecov/project 33.35% (No base report)
codecov/patch 100.00% >= target 80%
test / go (pull_request) Successful in 2m26s
1cce320778
[email protected] requires Node ^24.11.0 (uses RegExp.escape, a Node 24+
builtin). The reusable workflow was pinned at 280a4499, which ran the
job on Node 22, causing an unhandled rejection on every scheduled run
that crashed Renovate before it scanned any dependencies. Because the
rejection was unhandled rather than a caught fatal error, npx still
exited 0, so every run showed as 'success' while doing nothing -- no
Renovate PRs or Dependency Dashboard issue were ever created since it
was added in #12.

Bumps the pin to 95bdd86, which merges the Node 22->24 fix in
colibrisec/forgejo-workflows.

🔎 ojo scan results

Severity Count
🟠 HIGH 3
🟡 MEDIUM 2
🟢 LOW 1
⚪ UNKNOWN 1
Details (7)
Type Severity ID/Rule Location Description
sast 🟠 HIGH go-ssrf internal/integrations/jira.go:67 http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
sast 🟠 HIGH go-ssrf internal/integrations/jira.go:101 http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
sast 🟠 HIGH go-ssrf internal/integrations/jira.go:141 http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
vuln 🟡 MEDIUM CVE-2026-84373 @vitest/[email protected] Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
vuln 🟡 MEDIUM CVE-2026-84373 [email protected] Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
misconfig 🟢 LOW dockerfile-no-healthcheck deploy/docker/Dockerfile:1 image has no HEALTHCHECK
vuln ⚪ UNKNOWN GO-2026-5932 golang.org/x/[email protected] The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
<!-- ojo-scan-summary --> ### 🔎 ojo scan results | Severity | Count | |---|---| | 🟠 HIGH | 3 | | 🟡 MEDIUM | 2 | | 🟢 LOW | 1 | | ⚪ UNKNOWN | 1 | <details><summary>Details (7)</summary> | Type | Severity | ID/Rule | Location | Description | |---|---|---|---|---| | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/1cce32077855d0e6f712ad5b3aa7ce35c23b10a6/internal/integrations/jira.go#L67" target="_blank" rel="noopener noreferrer">internal/integrations/jira.go:67</a> | http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/1cce32077855d0e6f712ad5b3aa7ce35c23b10a6/internal/integrations/jira.go#L101" target="_blank" rel="noopener noreferrer">internal/integrations/jira.go:101</a> | http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/1cce32077855d0e6f712ad5b3aa7ce35c23b10a6/internal/integrations/jira.go#L141" target="_blank" rel="noopener noreferrer">internal/integrations/jira.go:141</a> | http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | vuln | 🟡 MEDIUM | <a href="https://github.com/vitest-dev/vitest/security/advisories/GHSA-82fw-gwwq-j7x9" target="_blank" rel="noopener noreferrer">CVE-2026-84373</a> | @vitest/[email protected] | Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock | | vuln | 🟡 MEDIUM | <a href="https://github.com/vitest-dev/vitest/security/advisories/GHSA-82fw-gwwq-j7x9" target="_blank" rel="noopener noreferrer">CVE-2026-84373</a> | [email protected] | Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock | | misconfig | 🟢 LOW | dockerfile-no-healthcheck | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/1cce32077855d0e6f712ad5b3aa7ce35c23b10a6/deploy/docker/Dockerfile#L1" target="_blank" rel="noopener noreferrer">deploy/docker/Dockerfile:1</a> | image has no HEALTHCHECK | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/44226" target="_blank" rel="noopener noreferrer">GO-2026-5932</a> | golang.org/x/[email protected] | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | </details>

Codecov Results 📊

✅ Patch coverage is 100.00%. Project has 4737 uncovered lines.


Generated by Codecov Action

<!-- codecov-action-results --> ## Codecov Results 📊 :white_check_mark: Patch coverage is **100.00%**. Project has **4737** uncovered lines. --- *Generated by [Codecov Action](https://github.com/getsentry/codecov-action)*
james merged commit 39c93e5374 into main 2026-09-19 14:31:59 +00:00
james deleted branch fix/renovate-node-version-pin 2026-09-19 14:32:00 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/balam!23
No description provided.