Skip to content

[INTER-2067] Ecosystem care - #355

Open
TheUnderScorer wants to merge 32 commits into
mainfrom
feature/INTER-2067-care
Open

TheUnderScorer wants to merge 32 commits into
mainfrom
feature/INTER-2067-care

Conversation

@TheUnderScorer

@TheUnderScorer TheUnderScorer commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This pull request introduces several improvements and maintenance updates across the repository, focusing on dependency upgrades, workflow enhancements, repository naming consistency, and build tooling. The main highlights include upgrading AWS SDK clients, updating CI workflows for better reliability and maintainability, and aligning repository references to the new naming convention.

Dependency and Build Tooling Updates:

  • Upgraded AWS SDK Clients to the latest version (^3.1144.0) for @fingerprint/aws-cloudfront-proxy.
  • Introduced a new build-utils/license.ts utility to generate the license banner dynamically, replacing the static assets/license_banner.txt file. [1] [2]

Continuous Integration and Workflow Improvements:

  • Updated all references to pnpm/action-setup in GitHub Actions workflows to use a specific commit for v6.1.0. [1] [2] [3] [4]
  • Upgraded actions/checkout to v5 and pinned cfn-guard installation to version 3.2.1 in the CloudFormation validation workflow for stability.

Repository Naming and Documentation Consistency:

  • Updated repository references from fingerprintjs/cloudfront-proxy to fingerprintjs/aws-cloudfront-proxy in changelogs, documentation, and configuration files for consistency with the new repo name. [1] [2]
  • Updated documentation links in Terraform variables and contributing guidelines to point to the new documentation URLs and clarify release triggers. [1] [2]

Build and Linting Configuration:

  • Migrated to ESLint 10.
  • Migrated build and testing system to Vite + Vitest.

TheUnderScorer and others added 7 commits October 1, 2026 12:35
Pin pnpm 11 via corepack `packageManager` and drop the hand-pinned
`version: 9` inputs from the workflows that set up pnpm. Align
`engines.node` and `@types/node` with the Node 24 Lambda runtime, bump
`actions/checkout` to v5, and pin the cfn-guard installer to a tagged
release instead of the repository's main branch.

Also removes the inert Dependabot config (Snyk covers dependency
updates), the Yarn-only `resolutions` field and the `main` entry that
pointed at a non-existent file, and corrects the changelog repository
slug, the stale `nodejs16.x` test fixture, the documented release
trigger, the `dev.fingerprint.com` doc links and the README
requirements.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
It was only available transitively through
@fingerprintjs/eslint-config-dx-team, so the lint script relied on a
binary that a clean install does not expose.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@TheUnderScorer TheUnderScorer self-assigned this Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Coverage report

St.❔
Category Percentage Covered / Total
🟢 Statements 90.88% 598/658
🟢 Branches 85.13% 269/316
🟢 Functions 91.45% 139/152
🟢 Lines 90.81% 583/642

Test suite run success

214 tests passing in 64 suites.

Report generated by 🧪jest coverage report action from f79de57

Show full coverage report
St File % Stmts % Branch % Funcs % Lines Uncovered Line #s
🟢 All files 90.88 85.12 91.44 90.8
🟢  mgmt-lambda 98.73 95.74 100 98.73
🟢   ...ltSettings.ts 100 100 100 100
🟢   app.ts 97.36 96.42 100 97.36 31
🟢   auth.ts 100 100 100 100
🟢   exceptions.ts 100 0 100 100 20
🟢   routing.ts 100 100 100 100
🟢  ...ambda/handlers 85.97 72.58 93.33 85.88
🟢   errorHandlers.ts 100 70 100 100 22-38,47
🟡   statusHandler.ts 76.92 50 100 76.92 78-82,86-91
🟢   updateHandler.ts 86.5 76.08 87.5 86.4 ...24,286-287,321
🟡  mgmt-lambda/utils 70 83.33 66.66 62.5
🟢   ...frontUtils.ts 100 83.33 100 100 7
🔴   delay.ts 25 100 0 25 2-4
🟢  proxy/handlers 98.21 86.66 100 98.21
🟢   handleIngress.ts 96.96 85 100 96.96 65
🟢   handleStatus.ts 100 88 100 100 58,72
🟡  proxy/test 66.66 100 50 66.66
🟡   aws.ts 66.66 100 50 66.66 4-5
🟢  ...omer-variables 100 100 100 100
🟢   ...-variables.ts 100 100 100 100
🟢  proxy/utils 88.09 80.61 90 88.11
🟢   buffer.ts 100 50 100 100 2
🟢   cache-control.ts 100 100 100 100
🟢   cache.ts 100 87.5 100 100 17
🟢   cookie.ts 100 100 100 100
🔴   ...orResponse.ts 16.66 100 25 18.18 15-30
🟢   headers.ts 95.45 90.69 100 95.16 241-243
🔴   is-blob.ts 0 0 0 0 7
🟢   is-truthy.ts 100 100 100 100
🟡   log.ts 80 50 100 75 11
🟢   paths.ts 100 87.5 100 100 20
🟢   request.ts 92 75 87.5 91.3 8-9
🟢   routing.ts 100 100 100 100
🔴   string.ts 0 100 0 0 2-8
🟢   traffic.ts 100 100 100 100
🟢   transport.ts 92 66.66 100 92 35,60
🟢   validation.ts 100 100 100 100
🟢  ...omer-variables 98.5 100 95.45 98.41
🟢   ...-variables.ts 100 100 100 100
🟢   defaults.ts 100 100 100 100
🟢   ...-variables.ts 100 100 100 100
🟢   ...e-variable.ts 100 100 100 100
🟢   selectors.ts 95.45 100 90 95 31
🟢   types.ts 100 100 100 100
🟢  ...ecrets-manager 93.44 94.73 100 93.33
🟢   ...ize-secret.ts 83.33 75 100 80 5
🟢   ...eve-secret.ts 100 100 100 100
🟢   ...-variables.ts 86.36 93.33 100 86.36 36,64-69
🟢   ...ate-secret.ts 100 100 100 100

@TheUnderScorer
TheUnderScorer force-pushed the feature/INTER-2067-care branch from 9c952c8 to 105e40c Compare October 1, 2026 12:19
Applied consistent use of `.ts` extensions, enabled `allowImportingTsExtensions`, added ESLint rules for type consistency, and updated related tooling configurations.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Empty-value fallback and CloudFront readiness regressions can break proxy requests and make E2E tests unreliable.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity · 1 Low severity

Open (4)
What changed in this PR

Modernizes the project’s Node.js ecosystem, build pipeline, testing stack, linting, and dependencies while retaining the Lambda deployment structure.

Changes:

  • Migrates Rollup/Jest to Vite/Vitest and Node.js 24.
  • Upgrades AWS SDK, TypeScript, ESLint, pnpm, and E2E tooling.
  • Refactors type safety, module imports, workflows, and documentation.
File Description
vitest.setup.ts Adds AWS mock matchers.
vitest.config.ts Configures Vitest and coverage.
vite.config.ts Adds Lambda bundle configuration.
vite-env.d.ts Declares build-time globals.
tsconfig.json Adopts bundler-oriented type checking.
tsconfig.eslint.json Adds ESLint TypeScript project.
scripts/​downloadGithubRelease.mjs Applies formatting cleanup.
rollup.config.js Removes obsolete Rollup configuration.
README.md Documents region and runtime requirements.
proxy/​utils/​validation.ts Simplifies integer validation.
proxy/​utils/​transport.ts Improves imports and error typing.
proxy/​utils/​traffic.ts Uses the build-time version global.
proxy/​utils/​request.ts Strengthens region validation.
proxy/​utils/​paths.ts Clarifies loader-version handling.
proxy/​utils/​log.ts Updates typed imports.
proxy/​utils/​is-blob.ts Simplifies Blob detection.
proxy/​utils/​index.ts Adds explicit TypeScript extensions.
proxy/​utils/​headers.ts Tightens header handling.
proxy/​utils/​customer-variables/​types.ts Updates parser typing.
proxy/​utils/​customer-variables/​selectors.ts Handles empty selector values explicitly.
proxy/​utils/​customer-variables/​secrets-manager/​validate-secret.ts Improves secret validation typing.
proxy/​utils/​customer-variables/​secrets-manager/​secrets-manager-variables.ts Removes unsafe secret assertions.
proxy/​utils/​customer-variables/​secrets-manager/​retrieve-secret.ts Updates imports and nullish handling.
proxy/​utils/​customer-variables/​secrets-manager/​normalize-secret.ts Validates parsed JSON shape.
proxy/​utils/​customer-variables/​maybe-obfuscate-variable.ts Clarifies obfuscation conditions.
proxy/​utils/​customer-variables/​header-customer-variables.ts Refactors Promise return.
proxy/​utils/​customer-variables/​defaults.ts Uses build-time endpoint globals.
proxy/​utils/​customer-variables/​customer-variables.ts Refines nullable variable resolution.
proxy/​utils/​cache.ts Updates import extension.
proxy/​utils/​buffer.ts Supports Uint8Array payloads.
proxy/​test/​utils/​traffic.test.ts Updates imports for Vitest.
proxy/​test/​utils/​routing.test.ts Updates imports for Vitest.
proxy/​test/​utils/​request.test.ts Updates imports and types.
proxy/​test/​utils/​headers.test.ts Updates imports and types.
proxy/​test/​utils/​customer-variables/​selectors.test.ts Migrates AWS mock matchers.
proxy/​test/​utils/​customer-variables/​secrets-manager/​validate-secret.test.ts Updates assertions and messages.
proxy/​test/​utils/​customer-variables/​secrets-manager/​retrieve-secret.test.ts Migrates timers to Vitest.
proxy/​test/​utils/​customer-variables/​maybe-obfuscate-variable.test.ts Updates import extensions.
proxy/​test/​utils/​customer-variables/​in-memory-customer-variables.ts Updates test provider typing.
proxy/​test/​utils/​customer-variables/​customer-variables.test.ts Migrates mocks to Vitest.
proxy/​test/​utils/​cookie.test.ts Updates import extension.
proxy/​test/​utils/​cache.test.ts Migrates timers to Vitest.
proxy/​test/​utils/​cache-control.test.ts Updates import extension.
proxy/​test/​handlers/​v4/​handleIngress.test.ts Migrates spies and mocks.
proxy/​test/​handlers/​v4/​handleBrowserCache.test.ts Migrates HTTP request spies.
proxy/​test/​handlers/​v4/​handleAgentDownloading.test.ts Migrates mocks to Vitest.
proxy/​test/​handlers/​handleStatus.test.ts Updates import extensions.
proxy/​test/​handlers/​handleResult.test.ts Migrates spies and mocks.
proxy/​test/​handlers/​handleAgentDownloading.test.ts Migrates mocks to Vitest.
proxy/​test/​handlers/​__snapshots__/​handleStatus.test.ts.snap Converts snapshots to Vitest format.
proxy/​test/​aws.ts Makes AWS imports type-only.
proxy/​model/​ResultOptions.ts Updates type-only imports.
proxy/​model/​index.ts Separates type and runtime exports.
proxy/​model/​AgentOptions.ts Makes HTTP import type-only.
proxy/​handlers/​handleStatus.ts Uses build globals and explicit checks.
proxy/​handlers/​handleIngress.ts Improves typing and request switching.
proxy/​app.ts Updates imports and route checks.
pnpm-workspace.yaml Allows the esbuild install script.
package.json Upgrades tooling and runtime dependencies.
mgmt-lambda/​utils/​delay.ts Expands delay callback.
mgmt-lambda/​utils/​cloudfrontUtils.ts Improves AWS type handling.
mgmt-lambda/​test/​handlers/​handleUpdate.test.ts Migrates update tests to Vitest.
mgmt-lambda/​test/​handlers/​handleStatus.test.ts Migrates status tests to Vitest.
mgmt-lambda/​test/​auth.test.ts Migrates auth tests to Vitest.
mgmt-lambda/​test/​app.test.ts Migrates application tests to Vitest.
mgmt-lambda/​handlers/​updateHandler.ts Tightens AWS response validation.
mgmt-lambda/​handlers/​statusHandler.ts Updates imports and nullish handling.
mgmt-lambda/​handlers/​errorHandlers.ts Improves unknown-error handling.
mgmt-lambda/​auth.ts Strengthens secret and token typing.
mgmt-lambda/​app.ts Updates imports and async handling.
jest.config.js Removes obsolete Jest configuration.
eslint.config.mjs Adds flat, type-aware ESLint configuration.
e2e/​website/​src/​main.ts Refactors browser event handling.
e2e/​website/​package.json Upgrades website dependencies.
e2e/​tests/​src/​utils/​wait.ts Adds explicit Promise typing.
e2e/​tests/​src/​utils/​terraform.ts Adds ESM __dirname support.
e2e/​tests/​src/​utils/​playwright.ts Uses type-only imports.
e2e/​tests/​src/​utils/​cloudfront.ts Refactors E2E readiness utilities.
e2e/​tests/​src/​utils/​checkResponse.ts Updates imports and types.
e2e/​tests/​src/​tests/​visitorId.test.ts Updates E2E imports.
e2e/​tests/​src/​tests/​v4/​visitorId.test.ts Improves assertion diagnostics.
e2e/​tests/​src/​tests/​statusCheck.test.ts Updates E2E imports.
e2e/​tests/​src/​project.ts Updates type import.
e2e/​tests/​src/​cloudfrontTest.ts Separates type imports.
e2e/​tests/​playwright.config.ts Updates imports and CI checks.
e2e/​tests/​package.json Migrates E2E tests to ESM.
e2e/​scripts/​mockTests.ts Uses native TypeScript execution.
e2e/​infra/​terraform/​variables.tf Updates documentation links.
e2e/​infra/​terraform/​tests.tf Uses the new mock-test script.
CONTRIBUTING.md Corrects release documentation.
commitlint.config.mjs Adds ESM commitlint configuration.
commitlint.config.js Removes CommonJS commitlint configuration.
CHANGELOG.md Corrects repository links.
build-utils/​license.ts Generates bundle license banners.
assets/​license_banner.txt Removes legacy banner template.
.husky/​pre-push Adds shell declaration.
.husky/​pre-commit Updates lint-staged hook.
.husky/​commit-msg Updates commitlint hook.
.github/​workflows/​terraform-e2e-tests-on-dev.yml Upgrades pnpm setup action.
.github/​workflows/​publish-lambda.yml Upgrades pnpm setup action.
.github/​workflows/​coverage-diff.yml Configures Vitest coverage command.
.github/​workflows/​check-cloudformation.yml Upgrades checkout and pins cfn-guard.
.github/​dependabot.yml Removes Dependabot configuration.
.eslintrc.js Removes legacy ESLint configuration.
.changeset/​pre.json Enters release-candidate mode.
.changeset/​deps-update.md Records AWS SDK upgrades.
.changeset/​config.json Corrects repository metadata.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread proxy/utils/customer-variables/customer-variables.ts Outdated
Comment thread e2e/tests/src/utils/cloudfront.ts
Comment thread e2e/tests/src/utils/cloudfront.ts Outdated
Comment thread e2e/website/src/main.ts Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Secret validation may leak sensitive contents, while E2E URL/retry handling and Guard version pinning contain correctness issues.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
Resolved since last review (4)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Pin the installed Guard binary version

.github/​workflows/​check-cloudformation.yml:19

Pinning the installer URL does not pin the installed Guard binary: this script fetches the latest release unless it receives -v. Pass 3.2.1 explicitly so CI does not change behavior when a newer Guard release appears.

Comment thread proxy/utils/customer-variables/secrets-manager/validate-secret.ts Outdated
Comment thread e2e/tests/src/utils/cloudfront.ts Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A guaranteed failing validation test and an empty environment-variable regression remain unresolved.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (2)

Comment thread proxy/test/utils/customer-variables/secrets-manager/validate-secret.test.ts Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Empty E2E URL variables are mishandled, and the cfn-guard workflow does not actually pin the installed binary.

Review effort: Balanced
Findings: None

Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Pin the installed cfn-guard version

.github/​workflows/​check-cloudformation.yml:19

Pinning only the installer URL does not pin the installed cfn-guard version: this tagged script defaults to querying GitHub's latest release when no -v argument is supplied. Pass -v 3.2.1 so CI remains reproducible and does not silently execute a newer binary.

Comment thread .github/workflows/check-cloudformation.yml Outdated
@TheUnderScorer
TheUnderScorer marked this pull request as ready for review October 2, 2026 10:55
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🚀 Following releases will be created using changesets from this PR:

@fingerprint/aws-cloudfront-proxy@2.2.1-rc.0

Patch Changes

  • Upgrade AWS SDK Clients to latest version (^3.1144.0). (51192a4)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants