deps: upgrade dependencies and add a JS runtime for yt-dlp #3

Merged
fmartingr merged 4 commits from update-dockerfile-deps into master 2026-10-02 13:10:18 +02:00
Owner

Upgrades every dependency in the code and the packaging, and adds a JS runtime to the container image so yt-dlp can solve YouTube JS challenges.

Code

  • Go server: modernc.org/sqlite 1.59.0 → 1.60.1, modernc.org/libc 1.77.1, xstrings 1.6.2, go-strftime 1.1.0 (all indirect; no direct module had a newer version).
  • Go e2e: moby/moby/api 1.56.1, moby/moby/client 0.6.1, gopsutil 4.26.9, klauspost/compress 1.20.1.
  • Webapp: vite 8.3.2, @tabler/icons-vue 3.48.0, dompurify 3.4.16, eslint-plugin-vue 10.11.1.
  • TypeScript 5.9.3 → 6.0.3. Version 6 is now stable and inside the typescript-eslint range (<6.1.0). TypeScript 7 still breaks typescript-eslint.
  • package-lock.json stays on lockfile format v2 to keep the diff small.

Packaging and CI

  • Alpine 3.23 → 3.24 in Containerfile and e2e/Dockerfile.e2e.
  • docker:27-dind → docker:29-dind for the e2e CI service.
  • goreleaser-action v6.4.0 → v7.2.3, setup-qemu-action / setup-buildx-action v3 → v4. The only breaking change in their release notes is the Node 24 runtime.
  • golangci-lint v2.13.2 → v2.14.0.

JS runtime for yt-dlp

yt-dlp solves YouTube JS challenges with yt-dlp-ejs and a JS runtime.

  • amd64 and arm64: the image installs deno and yt-dlp-ejs.
  • armv7: Alpine ships no deno for armv7 (3.24 or edge). The image installs nodejs and writes --js-runtimes node to /etc/yt-dlp.conf, because yt-dlp only runs deno unless told otherwise. hako does not pass --ignore-config, so the file applies.

Verification

  • go test -race ./..., e2e go vet, golangci-lint v2.14.0 (0 issues).
  • eslint, vite build, goreleaser check.
  • Built the Containerfile for linux/amd64, linux/arm64 and linux/arm/v7. yt-dlp -v reports JS runtimes: deno-2.7.4 on amd64/arm64 and node-24.18.1 on armv7.
  • A real YouTube URL on amd64 resolved formats with deno as the JS challenge provider. Not tested on arm64 or armv7.
  • The e2e suite was not run locally.

Known issues

  • Docker 29 dind is not tested yet. The e2e job starts containerd and dockerd with a custom command; this PR's CI run will show if it still works.
  • vue-tsc reports 9 type errors, all also present on master: the 8 known from #2, plus process in vite.config.ts (no @types/node). TypeScript 5.9.3 gives the same error.
Upgrades every dependency in the code and the packaging, and adds a JS runtime to the container image so yt-dlp can solve YouTube JS challenges. ## Code - **Go server:** `modernc.org/sqlite` 1.59.0 → 1.60.1, `modernc.org/libc` 1.77.1, `xstrings` 1.6.2, `go-strftime` 1.1.0 (all indirect; no direct module had a newer version). - **Go e2e:** `moby/moby/api` 1.56.1, `moby/moby/client` 0.6.1, `gopsutil` 4.26.9, `klauspost/compress` 1.20.1. - **Webapp:** `vite` 8.3.2, `@tabler/icons-vue` 3.48.0, `dompurify` 3.4.16, `eslint-plugin-vue` 10.11.1. - **TypeScript 5.9.3 → 6.0.3.** Version 6 is now stable and inside the `typescript-eslint` range (`<6.1.0`). TypeScript 7 still breaks `typescript-eslint`. - `package-lock.json` stays on lockfile format v2 to keep the diff small. ## Packaging and CI - **Alpine 3.23 → 3.24** in `Containerfile` and `e2e/Dockerfile.e2e`. - **`docker:27-dind` → `docker:29-dind`** for the e2e CI service. - **`goreleaser-action` v6.4.0 → v7.2.3**, **`setup-qemu-action` / `setup-buildx-action` v3 → v4**. The only breaking change in their release notes is the Node 24 runtime. - **`golangci-lint` v2.13.2 → v2.14.0.** ## JS runtime for yt-dlp yt-dlp solves YouTube JS challenges with `yt-dlp-ejs` and a JS runtime. - **amd64 and arm64:** the image installs `deno` and `yt-dlp-ejs`. - **armv7:** Alpine ships no deno for armv7 (3.24 or edge). The image installs `nodejs` and writes `--js-runtimes node` to `/etc/yt-dlp.conf`, because yt-dlp only runs deno unless told otherwise. hako does not pass `--ignore-config`, so the file applies. ## Verification - `go test -race ./...`, e2e `go vet`, `golangci-lint` v2.14.0 (0 issues). - `eslint`, `vite build`, `goreleaser check`. - Built the `Containerfile` for `linux/amd64`, `linux/arm64` and `linux/arm/v7`. `yt-dlp -v` reports `JS runtimes: deno-2.7.4` on amd64/arm64 and `node-24.18.1` on armv7. - A real YouTube URL on amd64 resolved formats with deno as the JS challenge provider. Not tested on arm64 or armv7. - The e2e suite was not run locally. ## Known issues - **Docker 29 dind** is not tested yet. The e2e job starts `containerd` and `dockerd` with a custom command; this PR's CI run will show if it still works. - **`vue-tsc` reports 9 type errors, all also present on `master`:** the 8 known from #2, plus `process` in `vite.config.ts` (no `@types/node`). TypeScript 5.9.3 gives the same error.
- Go: modernc.org/sqlite 1.60.1, modernc.org/libc 1.77.1 and other
  indirect modules; e2e moby api/client, gopsutil and compress.
- Webapp: vite 8.3.2, @tabler/icons-vue 3.48.0, dompurify 3.4.16,
  eslint-plugin-vue 10.11.1 and TypeScript 6.0.3, the highest version
  that typescript-eslint supports (<6.1.0).
- Images: Alpine 3.24 for the release and e2e images, docker:29-dind
  for the e2e CI service.
- CI: goreleaser-action v7.2.3, setup-qemu-action v4,
  setup-buildx-action v4 and golangci-lint v2.14.0.
feat: install a JS runtime for yt-dlp challenge solving
Some checks failed
CI / goreleaser-lint (pull_request) Successful in 8s
CI / format (pull_request) Successful in 47s
CI / lint (pull_request) Successful in 5m40s
CI / test (pull_request) Successful in 6m46s
CI / build (pull_request) Successful in 7m7s
CI / e2e (pull_request) Failing after 9m46s
07a2c61343
yt-dlp solves YouTube JS challenges with yt-dlp-ejs and a JS runtime.
The image installs deno and yt-dlp-ejs on amd64 and arm64.

Alpine ships no deno for armv7, so that image installs nodejs and
enables it in /etc/yt-dlp.conf, because yt-dlp only runs deno unless
told otherwise.
ci: run the e2e dind service on the overlay2 storage driver
All checks were successful
CI / goreleaser-lint (pull_request) Successful in 8s
CI / format (pull_request) Successful in 1m37s
CI / lint (pull_request) Successful in 4m5s
CI / test (pull_request) Successful in 5m16s
CI / build (pull_request) Successful in 5m44s
CI / e2e (pull_request) Successful in 31m20s
199837b5df
Docker 29 defaults to the containerd image store, which keeps layers in
/var/lib/containerd on the dind container's own overlayfs. Nested
overlay mounts fail there with "invalid argument", so every e2e image
build failed. Disable the containerd snapshotter so dockerd uses
overlay2 in the /var/lib/docker volume.
Merge branch 'master' into update-dockerfile-deps
All checks were successful
CI / goreleaser-lint (pull_request) Successful in 8s
CI / format (pull_request) Successful in 2m17s
CI / lint (pull_request) Successful in 4m26s
CI / test (pull_request) Successful in 6m51s
CI / build (pull_request) Successful in 3m2s
CI / e2e (pull_request) Successful in 25m24s
f0a0188cef
fmartingr merged commit 70b0896183 into master 2026-10-02 13:10:18 +02:00
fmartingr deleted branch update-dockerfile-deps 2026-10-02 13:10:18 +02:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
fmartingr/hako!3
No description provided.