deps: upgrade server, webapp and e2e dependencies #2

Merged
fmartingr merged 8 commits from chore/upgrade-deps into master 2026-09-22 20:10:10 +02:00

2026-09-22

ci: start containerd before dockerd in the e2e service
All checks were successful
CI / goreleaser-lint (pull_request) Successful in 10s
CI / format (pull_request) Successful in 1m30s
CI / lint (pull_request) Successful in 4m43s
CI / test (pull_request) Successful in 6m59s
CI / build (pull_request) Successful in 6m25s
CI / e2e (pull_request) Successful in 25m10s
Retrying dockerd was a coin flip. containerd needs a little over ten
seconds to boot in the runner's container and dockerd waits exactly
ten, so every attempt loses that race when the host is busy: run 19
burned all five and the job waited three minutes for a daemon that
never arrived.

Starting containerd first and handing dockerd the socket removes the
timeout from the picture. Measured on the runner: ready in 30 seconds,
no retries.
2026-09-22 19:27:51 +02:00
ci: run golangci-lint at the pinned version
Some checks failed
CI / goreleaser-lint (pull_request) Successful in 1m2s
CI / format (pull_request) Successful in 2m44s
CI / test (pull_request) Successful in 4m27s
CI / build (pull_request) Successful in 3m36s
CI / lint (pull_request) Successful in 6m24s
CI / e2e (pull_request) Failing after 3m32s
The ci-lint target guarded its install with `which golangci-lint`, so on a
runner that already ships golangci-lint the pinned version was never
installed and whatever the image carried ran instead. That binary is v1,
which cannot read a `version: "2"` config and exits with "can't load
config: unsupported version of the configuration".

This is why lint fails on master as well, and why it started failing at
ccda656c ("ci: run workflows on the GitHub-compatible runner") while the
target itself has not changed since.

Always installs the pinned version and invokes it by absolute path, so
the result no longer depends on what the runner image happens to carry.

Verified in a golang:1.26 container both clean and with a decoy
golangci-lint ahead of it on PATH; the old target picks up the decoy and
fails, the new one does not.
2026-09-22 18:11:37 +02:00
Merge origin/master into chore/upgrade-deps
Some checks failed
CI / goreleaser-lint (pull_request) Successful in 9s
CI / format (pull_request) Successful in 1m11s
CI / build (pull_request) Successful in 6m40s
CI / test (pull_request) Successful in 7m41s
CI / e2e (pull_request) Has been cancelled
CI / lint (pull_request) Has been cancelled
Master migrated CI to Forgejo Actions and, independently, fixed the same
three e2e failures this branch did. Resolution takes master's side for CI
and e2e infrastructure and keeps this branch's dependency upgrades.

Superseded by master, dropped from this branch:
- .woodpecker pipelines, deleted in favour of .github/workflows. The
  branch gating and Go version bumps made here are moot: the workflows
  already target master and read go-version-file from go.mod.
- The host-gateway route added to reach the test web server. Master's
  shared Docker network with a container alias is the better fix; it does
  not depend on Docker Desktop and works under the Docker-in-Docker
  service the new e2e job uses. e2eutil/hostgateway.go is removed.
- Local formatting of e2e/e2eutil/helper.go, to keep master's file intact.

Kept from this branch:
- All dependency upgrades, including e2e on testcontainers 0.44 rather
  than master's 0.40. Master's container.go still called MappedPort with
  a nat.Port; 0.44 takes a string, so its call is adapted and the
  go-connections import dropped.
- golangci-lint v2.13.2 on the /v2 module path. Master left the v1.64.5
  pin and the pre-v2 path against a `version: "2"` config, so `make
  ci-lint` would still fail.

Both sides reached the same conclusions on the selector, CreateLink
navigation and IsVisible strict-mode fixes; master's wording of each is
kept. Containerfile stays on master's Alpine 3.23.
2026-09-22 17:37:53 +02:00
test(e2e): upgrade dependencies and fix archive tests
Upgrades testcontainers 0.40 -> 0.44, otel 1.39 -> 1.46 and playwright-go
0.5200.1 -> 0.6201.1, which also moves to its renamed module path.
MappedPort now takes a string rather than a nat.Port.

Fixes three pre-existing failures, all confirmed against a pristine
worktree at master with the old dependency set:

Hako archives a link by issuing a synchronous HEAD request from inside
its own container, so the test web server's host-published port was
unreachable over localhost and every creation returned 500. The container
now gets a host-gateway entry and the target URL is addressed through it.

CreateLink returns to /home before filling the form. A successful submit
redirects to /links, so tests that create several links could no longer
find the input; the redirect branch in the helper had never been reached
while creation was failing. The navigation is conditional to avoid racing
a page load the caller just started.

Tests clicked `a[href*='/links/']`, which matches nothing because a link
card is a div with a click handler, and IsVisible tripped Playwright's
strict mode on grouped selectors that legitimately match several
elements.
2026-09-22 12:08:36 +02:00
ci: fix branch gating, lint pin and toolchain versions
Both pipelines gated on `branch: main` while origin/HEAD is master, so
neither had been running.

ci-lint pinned golangci-lint v1.64.5 against a `version: "2"` config, and
used the pre-v2 module path. Moves to v2.13.2 and the /v2 path.

Go images trailed go.mod (golang:1.24 in CI, go1.23.5 in release), which
left GOTOOLCHAIN re-downloading a toolchain on every run. Both move to
1.27.

Alpine goes 3.20 -> 3.24 in both the release image and the e2e image.

Playwright's Go module was renamed upstream to github.com/mxschmitt, so
the driver install commands follow it; the old path resolves to a version
whose go.mod declares the new name and fails.
2026-09-22 12:08:25 +02:00
fix(webapp): inherit compiler options in tsconfig.app.json
tsconfig.app.json extended ./tsconfig.json, which is a solution file
holding only `files: []` and `references`. It therefore inherited no
target, lib, jsx or noEmit, so type checks failed on every built-in type
("Cannot find name 'Map'") and vue-tsc -b emitted JavaScript next to the
TypeScript sources, which then shadowed them and broke `vite build`.

Extends @vue/tsconfig/tsconfig.dom.json (already a devDependency, until
now unused) and sets noEmit explicitly.

Note vue-tsc must run under node; under `bun --bun` it fails to resolve
.vue modules at all.
2026-09-22 12:08:17 +02:00
deps: upgrade webapp dependencies
Major bumps: pinia 2 -> 4, vue-router 4 -> 5, vite 6 -> 8, eslint 9 -> 10,
vue-tsc 2 -> 3, @vitejs/plugin-vue 5 -> 6, pdfjs-dist 5 -> 6, marked 17 -> 18.

TypeScript stays on 5.9.3: typescript-eslint declares `typescript
>=4.8.4 <6.1.0` and refuses to load under TS 7, and TS 6 exists only as a
beta. 5.9.3 is the highest version that keeps `make lint-webapp` working.

Drops @codemirror/basic-setup (no importers) and @types/dompurify (an
npm-deprecated stub; dompurify ships its own types).

Vite 8 builds with rolldown, which rejects a type imported as a value, so
Extension moves to an `import type` in JsonEditor.
2026-09-22 12:08:11 +02:00
deps: upgrade server dependencies
Bumps every direct and indirect dependency to latest. Notable: goquery
1.9.2 -> 1.13.0, go-sqlbuilder 1.38.2 -> 1.43.0, cobra 1.9.1 -> 1.10.2,
testify 1.11.1 -> 1.12.1, x/crypto 0.46.0 -> 0.57.0, modernc.org/sqlite
1.34.1 -> 1.59.0.

The go directive moves to 1.26.0 because the golang.org/x modules now
require it.
2026-09-22 12:08:04 +02:00