| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
|
Claude review checkpoint
Reviewed commit 1a1e10e15a27a6ee20cfc48442b2d6a4b3a097b3. This is used to keep later automated reviews focused on changes Claude has not checked yet. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Summary
Closes #94
Replaces the all-or-nothing Bash deploy.sh with a standalone TypeScript CLI (deploy.mts, powered by Clack) that drives deployment of the customer-facing tracking scripts to the Bunny CDN and the app@external.simpleanalytics.com custom-domain server.
2026-08-05-14h45-screenshot.mp4Key behavior:
Also migrates the repo to pinned Node 24 / pnpm 11 with a strict supply-chain policy (pnpm-workspace.yaml: seven-day minimum release age, trust checks, exotic-subdep blocking, deny-by-default dependency builds), drops package-lock.json in favor of pnpm-lock.yaml, updates the BrowserStack workflow to pnpm, and adds test/deploy.test.mts covering the manifest, SRI transform, and preview helpers.
Changes:
Security implications
Has security impact - described as: changes the deployment path for production, customer-facing tracking scripts (CDN + custom domain), handles Bunny CDN credentials and SSH-based reads/writes to the external server, and introduces a supply-chain policy for dependency installation. Remote paths are validated and shell-quoted before use over SSH, and immutable SRI artifacts are protected against overwrite.
Testing
Not run by Claude. (Automated validation could not be executed in the review sandbox.)
Author-reported validation:
The intentionally retained legacy test/build dependency graph still has pre-existing audit findings; upgrading that stack is outside this PR.
Checklist