Skip to content

Sync: dev to main - #445

Merged
aamoghS merged 7 commits into
mainfrom
dev
Sep 30, 2026
Merged

aamoghS merged 7 commits into
mainfrom
dev

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Automated PR tracking changes from dev into main.


Note

Medium Risk
Changes affect how dependency bumps reach production, CDN caching for Hacklytics assets, and payment/membership confirmation plus hackathon admin flows.

Overview
This sync brings dev-branch dependency and promotion automation in line with how the repo actually ships: Dependabot now targets dev, auto-merge uses gh pr merge --auto --squash instead of the removed @dependabot merge comment, and the dev→main workflow adds a daily schedule plus a guard so it only opens a promotion PR when dev is ahead of main (covering merges that never fire a push workflow).

Hacklytics PR previews still run builds on Dependabot PRs but skip Firebase Hosting deploy when repo secrets are unavailable. firebase.json gives images a shorter cache TTL with stale-while-revalidate instead of the year-long immutable policy used for JS/CSS/fonts.

Application changes include next 16.3.7, moving startOfEasternDay into a shared eastern-time service export, safer hackathon registration errors (no raw exception text to clients), mass acceptance that does not re-accept checked-in participants on resend, judge results that clear the prior snapshot before recomputing, Stripe membership confirm that treats linking an unclaimed payment row as the grant (and skips grant if another request wins the link), and tRPC validation messages that surface Zod issue text instead of a JSON dump. Regenerated graphify-out artifacts ride along with the sync.

Reviewed by Cursor Bugbot for commit a9e1ec0. Bugbot is set up for automated code reviews on this repo. Configure here.

aamoghS and others added 5 commits September 30, 2026 12:21
- Target dev for both npm and github-actions bumps; main deploys to
  production.
- Skip the Firebase preview deploy on Dependabot PRs, which get no
  secrets; the build step still checks the bump.
- Replace the "@dependabot merge" comment, which GitHub removed on
  2026-01-27, with native auto-merge. The ruleset still requires a
  code-owner approval before it merges.
- Match on the PR author rather than github.actor.
- Bump next and @next/* to 16.3.7.
Error messages
- Stop showing members config details, raw DB errors and Zod issue
  dumps; the error formatter now surfaces the issue messages.
- Error boundaries and the Stripe webhook no longer echo internals.

Correctness
- computeResults replaces the unpublished snapshot instead of upserting,
  so a withdrawn project is never published with a stale placing.
- Resending acceptances leaves checked-in participants alone.
- An organiser-withdrawn project can no longer be resubmitted.
- Membership grants claim the payment first, so a double submit or two
  tabs cannot grant two years (confirm, reconcile, email auto-link).
- Email auto-link runs in a savepoint: a failure there used to roll back
  the whole login and bounce the user to /login.
- Registration-open emails repeat the claim conditions on the outer
  UPDATE, matching announce.ts.
- initializeQueue keeps completed slots; forceSkipOvertime refuses a
  finished slot; initiative status and review have state guards.
- Email lookups are case-insensitive, and unverified Google emails are
  refused before account linking.

Site
- Escape the Hacklytics JSON-LD; require Content-Length on csp-report.
- /events tolerates a sleeping DB and uses the Eastern day.
- Images cache for a day instead of forever (mainweb, Hacklytics, and
  the Hacklytics service worker); add the missing og-image.
- Payment modal cannot close mid-charge; smaller UI fixes.

Ops
- db:check also fails on a missing unique constraint.
- Listen for pool errors so a killed idle client is not uncaught.
Palette-quantize the PNGs and re-encode the JPGs: same dimensions and
transparency, largest per-pixel difference 40/255, 1.97 MB down to
0.88 MB. Also refreshes graphify-out.
Native auto-merge merges Dependabot PRs under GITHUB_TOKEN, and pushes
made with that token start no workflows, so the push trigger never saw
those merges. A daily run (and workflow_dispatch) opens the promotion PR
anyway, and exits cleanly when dev has nothing ahead of main.
…mpress

Feature: chore/hacklytics-image-compress to dev
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor Author

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
npm/next 16.3.7 🟢 6.4
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Binary-Artifacts⚠️ 0binaries present in source code
Packaging🟢 10packaging workflow detected
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
Fuzzing🟢 10project is fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@next/eslint-plugin-next 16.3.7 UnknownUnknown
npm/@next/bundle-analyzer 16.3.7 UnknownUnknown
npm/@next/env 16.3.7 UnknownUnknown
npm/@next/eslint-plugin-next 16.3.7 UnknownUnknown
npm/@next/swc-darwin-arm64 16.3.7 UnknownUnknown
npm/@next/swc-darwin-x64 16.3.7 UnknownUnknown
npm/@next/swc-linux-arm64-gnu 16.3.7 UnknownUnknown
npm/@next/swc-linux-arm64-musl 16.3.7 UnknownUnknown
npm/@next/swc-linux-x64-gnu 16.3.7 UnknownUnknown
npm/@next/swc-linux-x64-musl 16.3.7 UnknownUnknown
npm/@next/swc-win32-arm64-msvc 16.3.7 UnknownUnknown
npm/@next/swc-win32-x64-msvc 16.3.7 UnknownUnknown
npm/next 16.3.7 🟢 6.4
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Binary-Artifacts⚠️ 0binaries present in source code
Packaging🟢 10packaging workflow detected
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
Fuzzing🟢 10project is fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@next/eslint-plugin-next 16.3.7 UnknownUnknown
npm/next 16.3.7 🟢 6.4
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Binary-Artifacts⚠️ 0binaries present in source code
Packaging🟢 10packaging workflow detected
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
Fuzzing🟢 10project is fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@next/bundle-analyzer 16.3.7 UnknownUnknown
npm/@next/eslint-plugin-next 16.3.7 UnknownUnknown
npm/next 16.3.7 🟢 6.4
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Binary-Artifacts⚠️ 0binaries present in source code
Packaging🟢 10packaging workflow detected
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
Fuzzing🟢 10project is fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
npm/@next/eslint-plugin-next 16.3.7 UnknownUnknown
npm/@next/eslint-plugin-next 16.3.7 UnknownUnknown
npm/next 16.3.7 🟢 6.4
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Binary-Artifacts⚠️ 0binaries present in source code
Packaging🟢 10packaging workflow detected
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
Fuzzing🟢 10project is fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • package.json
  • packages/ui/package.json
  • pnpm-lock.yaml
  • sites/hacklytics2027/package.json
  • sites/mainweb/package.json
  • tooling/eslint/package.json
  • tooling/tailwind/package.json

@aamoghS
aamoghS added this pull request to stack #446 September 30, 2026 17:20
@aamoghS
aamoghS merged commit e0ae5e5 into main Sep 30, 2026
9 checks passed
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor Author

Visit the preview URL for this PR (updated for commit a9e1ec0):

https://hacklytics2027--pr-445-tj9rkz6c.web.app

(expires Wed, 07 Oct 2026 17:21:21 GMT)

🔥 via Firebase Hosting GitHub Action 🌎

Sign: c48ba34db61581e25fe2978355160b5eefe0e83f

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

⤵️ pull dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant