Repository navigation
Conversation
- Target dev for both npm and github-actions bumps; main deploys to production. - Skip the Firebase preview deploy on Dependabot PRs, which get no secrets; the build step still checks the bump. - Replace the "@dependabot merge" comment, which GitHub removed on 2026-01-27, with native auto-merge. The ruleset still requires a code-owner approval before it merges. - Match on the PR author rather than github.actor. - Bump next and @next/* to 16.3.7.
Error messages - Stop showing members config details, raw DB errors and Zod issue dumps; the error formatter now surfaces the issue messages. - Error boundaries and the Stripe webhook no longer echo internals. Correctness - computeResults replaces the unpublished snapshot instead of upserting, so a withdrawn project is never published with a stale placing. - Resending acceptances leaves checked-in participants alone. - An organiser-withdrawn project can no longer be resubmitted. - Membership grants claim the payment first, so a double submit or two tabs cannot grant two years (confirm, reconcile, email auto-link). - Email auto-link runs in a savepoint: a failure there used to roll back the whole login and bounce the user to /login. - Registration-open emails repeat the claim conditions on the outer UPDATE, matching announce.ts. - initializeQueue keeps completed slots; forceSkipOvertime refuses a finished slot; initiative status and review have state guards. - Email lookups are case-insensitive, and unverified Google emails are refused before account linking. Site - Escape the Hacklytics JSON-LD; require Content-Length on csp-report. - /events tolerates a sleeping DB and uses the Eastern day. - Images cache for a day instead of forever (mainweb, Hacklytics, and the Hacklytics service worker); add the missing og-image. - Payment modal cannot close mid-charge; smaller UI fixes. Ops - db:check also fails on a missing unique constraint. - Listen for pool errors so a killed idle client is not uncaught.
Palette-quantize the PNGs and re-encode the JPGs: same dimensions and transparency, largest per-pixel difference 40/255, 1.97 MB down to 0.88 MB. Also refreshes graphify-out.
Native auto-merge merges Dependabot PRs under GITHUB_TOKEN, and pushes made with that token start no workflows, so the push trigger never saw those merges. A daily run (and workflow_dispatch) opens the promotion PR anyway, and exits cleanly when dev has nothing ahead of main.
Feature: fix/dependabot-flow to dev
…mpress Feature: chore/hacklytics-image-compress to dev
Feature: fix/audit-hardening to dev
Contributor
Author
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF ScorecardScorecard details
Scanned Files
|
aamoghS
added this pull request to stack #446
September 30, 2026 17:20
Contributor
Author
|
Visit the preview URL for this PR (updated for commit a9e1ec0): https://hacklytics2027--pr-445-tj9rkz6c.web.app (expires Wed, 07 Oct 2026 17:21:21 GMT) 🔥 via Firebase Hosting GitHub Action 🌎 Sign: c48ba34db61581e25fe2978355160b5eefe0e83f |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated PR tracking changes from
devintomain.Note
Medium Risk
Changes affect how dependency bumps reach production, CDN caching for Hacklytics assets, and payment/membership confirmation plus hackathon admin flows.
Overview
This sync brings dev-branch dependency and promotion automation in line with how the repo actually ships: Dependabot now targets
dev, auto-merge usesgh pr merge --auto --squashinstead of the removed@dependabot mergecomment, and the dev→main workflow adds a daily schedule plus a guard so it only opens a promotion PR whendevis ahead ofmain(covering merges that never fire a push workflow).Hacklytics PR previews still run builds on Dependabot PRs but skip Firebase Hosting deploy when repo secrets are unavailable.
firebase.jsongives images a shorter cache TTL with stale-while-revalidate instead of the year-long immutable policy used for JS/CSS/fonts.Application changes include
next16.3.7, movingstartOfEasternDayinto a sharedeastern-timeservice export, safer hackathon registration errors (no raw exception text to clients), mass acceptance that does not re-accept checked-in participants on resend, judge results that clear the prior snapshot before recomputing, Stripe membership confirm that treats linking an unclaimed payment row as the grant (and skips grant if another request wins the link), and tRPC validation messages that surface Zod issue text instead of a JSON dump. Regeneratedgraphify-outartifacts ride along with the sync.Reviewed by Cursor Bugbot for commit a9e1ec0. Bugbot is set up for automated code reviews on this repo. Configure here.