Skip to content

v0.3.0

Choose a tag to compare

@henricook henricook released this 13 Aug 16:07
· 1 commit to main since this release

Dependency refresh across the board, plus the test suite that should have been guarding it.

Dependencies - zod 3 to 4, TypeScript 5 to 7 (the native Go compiler), @hono/node-server 1 to 2, and current releases of hono, dotenv, tsx and @types/node. Base images move to node:24-alpine (node:20 passed EOL in April 2026) and golang:1.26-alpine, and the GitHub Actions are on their current majors. No vulnerabilities reported.

Three majors needed code changes:

  • zod 4 removed ZodError.errors, so environment validation reports .issues
  • TypeScript 6+ no longer auto-includes @types/*, so tsconfig.json sets types: ["node"] explicitly
  • hono 4.13 types c.req.param() as possibly undefined, so sanitizeId now accepts string | undefined and the view route uses its return value

Tests - 41 tests on node:test via tsx, no new runtime dependency. Unit coverage of the ID and path sanitisers and of environment parsing (including the numeric coercion zod 4's .default() change could have silently broken), and an integration suite that boots the real server on an OS-assigned port against a temporary storage directory. That covers the upload and view round trip, every upload rejection path, ID validation and traversal payloads, generation marker invalidation and regeneration, and rate limiting including per-client keying.

Run with npm test, or npm run test:unit for the units alone. Integration tests need the cclogviewer binary; CI installs it. A new Test workflow runs typecheck and the full suite on every push and PR.

Upgrading - no configuration changes required. Note that rebuilding the image pulls cclogviewer@latest, so if upstream has moved since your last build, stored sessions will re-render on next view.