Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
58 commits
Select commit Hold shift + click to select a range
3ba9cb9
feat: reviewer skip via Redis skip set, atomic logSkip
calebmcquaid Jul 7, 2026
6f7e7f9
feat: single call skip with failure modal, drained queue redirect
calebmcquaid Jul 7, 2026
ef18452
add NCMEC field + integration tests (#887)
taobojlen Jul 7, 2026
2bb1e74
fix: Support non-standard scylla ports in DB Migrator (#878)
jess-upscrolled Jul 7, 2026
c5b0b48
chore(client): migrate test setup to Vitest 4 (#550)
serendipty01 Jul 7, 2026
2428fba
feat: add sepia filter (#62)
serendipty01 Jul 8, 2026
ee8eafe
chore: changelog update
calebmcquaid Jul 8, 2026
150c48b
Add Playwright E2E coverage for moderator flows (#875)
taobojlen Jul 13, 2026
b1e6fb1
ci(client): run frontend tests in CI (#891)
taobojlen Jul 13, 2026
b50b60d
ci: stop logging every DB query in test runs (#888)
taobojlen Jul 13, 2026
61a7e5e
test: migrate DB-backed tests to transactional harness (#821)
taobojlen Jul 14, 2026
919c6d0
test: Add MRT video playback E2E coverage (#890)
taobojlen Jul 14, 2026
610bcf0
Fix for Manual Review Tool: If createdAt datetime is in bad format, s…
julietshen Jul 15, 2026
e4238cd
Make Scylla-backed features (item investigation & user strikes) optio…
sunilatlas Jul 20, 2026
dd3f504
Scope zizmor workflow to only run when workflow files change (#924)
juanmrad Jul 20, 2026
1b2fb8c
Fix Oldest Task Age showing the newest job's age instead of the oldes…
dom-notion Jul 20, 2026
af4a838
Fix "Something Went Wrong" when opening MRT jobs with an unparseable …
julietshen Jul 21, 2026
40c58e0
refactor: remove hard-coded NCMEC test-org allowlist (#930)
taobojlen Jul 27, 2026
a8b5d36
build(deps): bump fast-uri (#939)
dependabot[bot] Jul 27, 2026
18fc618
build(deps): bump fast-uri (#938)
dependabot[bot] Jul 27, 2026
f9f9cc1
build(deps): bump undici from 7.27.1 to 7.29.0 in /client (#937)
dependabot[bot] Jul 27, 2026
0a2a033
build(deps): bump immutable from 5.1.5 to 5.1.9 (#936)
dependabot[bot] Jul 27, 2026
db73283
build(deps): bump protobufjs (#935)
dependabot[bot] Jul 27, 2026
6596a73
build(deps): bump axios (#926)
dependabot[bot] Jul 27, 2026
43843e2
build(deps-dev): bump knip in /db in the db-dev group across 1 direct…
dependabot[bot] Jul 27, 2026
343acbf
build(deps): bump markdown-it (#828)
dependabot[bot] Jul 27, 2026
d93125d
build(deps): bump the migrator-prod group across 1 directory with 2 u…
dependabot[bot] Jul 27, 2026
f1fcca4
build(deps-dev): bump the migrator-dev group across 1 directory with …
dependabot[bot] Jul 27, 2026
e7ddd4e
build(deps): bump the db-prod group across 1 directory with 6 updates…
dependabot[bot] Jul 27, 2026
b3e7c81
build(deps): bump nginx from 1.27-bookworm to 1.29.1-bookworm in /cli…
dependabot[bot] Jul 27, 2026
0fbd608
build: bump Node to 24.18.0 for June 2026 security releases (#905)
serendipty01 Jul 27, 2026
acc7b3a
build(deps-dev): bump js-yaml from 4.2.0 to 4.3.0 in /server (#862)
dependabot[bot] Jul 27, 2026
84a8485
build(deps-dev): bump brace-expansion from 5.0.6 to 5.0.8 (#934)
dependabot[bot] Jul 27, 2026
1694783
build(deps): bump ws from 8.20.0 to 8.21.1 in /client (#923)
dependabot[bot] Jul 27, 2026
ee6d126
build(deps-dev): bump js-yaml from 4.3.0 to 5.2.2 in /server (#946)
dependabot[bot] Jul 27, 2026
bd54a2e
build(deps): bump the server-prod-security group across 1 directory w…
dependabot[bot] Jul 27, 2026
0951a1a
build(deps): bump the nodejs-instrumentation-prod group across 1 dire…
dependabot[bot] Jul 27, 2026
4986ef7
build(deps-dev): bump postcss from 8.5.12 to 8.5.23 in /client (#940)
dependabot[bot] Jul 27, 2026
0ecffa3
Replace dotenv with Node's built-in --env-file-if-exists (#929)
taobojlen Jul 28, 2026
22d590e
build(deps-dev): bump the client-dev group across 1 directory with 19…
dependabot[bot] Jul 28, 2026
f23beb8
build(deps-dev): bump the server-dev group across 1 directory with 23…
dependabot[bot] Jul 28, 2026
ec65bb2
build(deps-dev): bump the root-dev group across 1 directory with 3 up…
dependabot[bot] Jul 28, 2026
4c8aa82
fix(mrt): collapse long text fields with Read more (#870) (#903)
taobojlen Jul 28, 2026
fd76bc2
Update npm deps with security vulnerabilities (#902)
taobojlen Jul 28, 2026
57f1c5c
Eliminate manual review history item refetches (#951)
taobojlen Jul 28, 2026
689edb0
Move related item query to its consumer (#952)
taobojlen Jul 28, 2026
386d2d2
Fix RetryFailedNcmecDecisionsJob to honor NCMEC_ENV (#928)
taobojlen Aug 3, 2026
c724aaa
Clarify npm rules in AGENTS.md (#953)
taobojlen Aug 3, 2026
09cf03a
fix: remove table constraint for NCMEC non-media submissions (#871)
calebmcquaid Aug 3, 2026
3b706ec
Refuse queue deletion when routing rules still reference it (#808)
reitblatt Aug 4, 2026
0aeb7eb
Add self-harm/intent + self-harm/instructions OpenAI signals (#535)
julietshen Aug 5, 2026
6e4a158
Disable max lines lint on tests files (#970)
juanmrad Aug 6, 2026
1eb63ca
log lock release failures
calebmcquaid Aug 6, 2026
b2c9010
test harness for reviewer-skip tests
calebmcquaid Aug 6, 2026
f02ab10
release the job lock inside recordReviewerSkip
calebmcquaid Aug 6, 2026
98f2f16
Merge remote-tracking branch 'origin/main' into caleb/670-per-reviewe…
calebmcquaid Aug 7, 2026
db04c28
remove changelog
calebmcquaid Aug 11, 2026
6110173
skipToNextJob, swallowing error fixes
calebmcquaid Aug 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .env.githubci
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ SCYLLA_HAS_ENTERPRISE_FEATURES='false'
GRAPHQL_MAX_DEPTH=10
EXPOSE_SENSITIVE_IMPLEMENTATION_DETAILS_IN_ERRORS=true
ALLOW_USER_INPUT_LOCALHOST_URIS=true
DATABASE_PRINT_LOGS=true
DATABASE_PRINT_LOGS=false

GROQ_SECRET_KEY=

Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/apply_pr_checks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -277,6 +277,9 @@ jobs:
- name: Lint client
run: docker compose run --rm --quiet-pull client npm run lint

- name: Test client
run: docker compose run --rm --quiet-pull client npm run test:prepush

- name: Build client
run: docker compose run --rm --quiet-pull client npm run build

Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/e2e.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -82,6 +82,7 @@ jobs:
cp server/.env.example server/.env
cp db/.env.example db/.env
cp client/.env.example client/.env
sed -i "s/^ITEM_QUEUE_TRAFFIC_PERCENTAGE=.*/ITEM_QUEUE_TRAFFIC_PERCENTAGE='1'/" server/.env

- name: Install dependencies
run: |
Expand Down Expand Up @@ -144,7 +145,7 @@ jobs:
PLAYWRIGHT_BASE_URL: http://localhost:3000

- name: Upload Playwright report
if: ${{ !cancelled() }}
if: ${{ failure() }}
uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
with:
name: playwright-report
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/zizmor.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,10 @@ name: GitHub Actions security analysis
on:
push:
branches: ['main']
paths: ['.github/workflows/**']
pull_request:
branches: ['**']
paths: ['.github/workflows/**']

concurrency:
group: zizmor-${{ github.ref }}
Expand Down
2 changes: 1 addition & 1 deletion .nvmrc
Original file line number Diff line number Diff line change
@@ -1 +1 @@
24.16.0
24.18.0
4 changes: 3 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -200,6 +200,8 @@ Two things differ from a local dev setup:

## Human-approval-required actions

Routine local setup and verification commands, including `npm ci` and existing build/test/lint/format/check scripts, do not require approval; the gates below apply to the changes being made, not merely to running commands.

Stop and get explicit human approval before:

- Changing license headers, copyright notices, or any legal text (including `LICENSE`).
Expand All @@ -208,7 +210,7 @@ Stop and get explicit human approval before:
- Deleting or renaming an existing GraphQL type or field — this breaks cached Apollo client state and any downstream consumer. Additive changes are usually safe; removals need a migration plan.
- Rewiring `server/iocContainer` in a way that changes service lifecycles or startup order — cascading effects on tests and boot.
- Auth, session, or request middleware (under `server/api.ts`) — security-sensitive; prefer a small, reviewable PR with explicit callouts.
- Adding, removing, or upgrading any library or package (including transitive dependencies in `package-lock.json`) — confirm licenses are compatible with Apache 2.0 and that there are no known CVEs.
- Adding, removing, or upgrading any dependency (including transitive dependencies in `package-lock.json`) — confirm licenses are compatible with Apache 2.0 and that there are no known CVEs.
- Multi-thousand-line diffs — ROOST policy is that reviewers can digest the change. Split into reviewable PRs; regenerated codegen and lockfile bumps are the only exceptions.

## Commit attribution
Expand Down
4 changes: 2 additions & 2 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
# Docker's cache will let us skip installs when the dependencies haven't changed.
# We build on debian because it has fewer dependency issues than Alpine for our
# native modules, and we don't really care about the larger image size.
FROM node:24.14.1-bullseye-slim AS server_base
FROM node:24.18.0-bullseye-slim AS server_base
WORKDIR /app
RUN apt-get update && apt-get install -y --no-install-recommends git && rm -rf /var/lib/apt/lists/*

Expand All @@ -19,7 +19,7 @@ FROM server_base AS build_backend
RUN npm run build

# make a shared layer that can be the base for worker and api images.
FROM node:24.14.1-bullseye-slim AS backend_base
FROM node:24.18.0-bullseye-slim AS backend_base
WORKDIR /app
RUN apt-get update && apt-get install dumb-init
COPY --from=build_backend ["/app/package.json", "/app/package-lock.json", "./"]
Expand Down
1 change: 1 addition & 0 deletions client/.dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -10,3 +10,4 @@
!tailwind.config.js
!tsconfig.json
!nginx.conf
!tsconfig.test.json
2 changes: 1 addition & 1 deletion client/.eslintrc.cjs
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ module.exports = {
extends: ['plugin:react/recommended', 'plugin:react-hooks/recommended'],
parser: '@typescript-eslint/parser',
parserOptions: {
project: ['./tsconfig.json'],
project: ['./tsconfig.json', './tsconfig.test.json'],
tsconfigRootDir: __dirname,
},
ignorePatterns: [
Expand Down
4 changes: 2 additions & 2 deletions client/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM node:24.14.1-bullseye-slim AS client_base
FROM node:24.18.0-bullseye-slim AS client_base
WORKDIR /app

# ARG is used to get the release id into the ENV from the command line, and then
Expand All @@ -20,7 +20,7 @@ ARG VITE_OTEL_EXPORTER_OTLP_TRACES_ENDPOINT
ENV DISABLE_ESLINT_PLUGIN=true
RUN NODE_OPTIONS="--max-old-space-size=5250" VITE_OTEL_EXPORTER_OTLP_TRACES_ENDPOINT=$VITE_OTEL_EXPORTER_OTLP_TRACES_ENDPOINT npm run build

FROM nginx:1.27-bookworm AS serve
FROM nginx:1.29.1-bookworm AS serve
COPY --from=build /app/build /usr/share/nginx/html
COPY nginx.conf /etc/nginx/conf.d/default.conf
EXPOSE 80
Expand Down
30 changes: 16 additions & 14 deletions client/eslint/__tests__/customRules.test.js
Original file line number Diff line number Diff line change
@@ -1,22 +1,24 @@
const { Linter } = require('eslint');
const rule = require('../no-casting-in-getFieldValueForRole');
import tsParser from '@typescript-eslint/parser';
import { Linter } from 'eslint';

const linter = new Linter();
import rule from '../no-casting-in-getFieldValueForRole.js';

const linter = new Linter({ configType: 'flat' });

const runLint = (code) => {
const messages = linter.verify(code, {
plugins: {
custom: {
rules: {
'no-casting-in-getFieldValueForRole': rule,
},
const messages = linter.verify(code, [
{
plugins: {
local: { rules: { 'no-casting-in-getFieldValueForRole': rule } },
},
rules: { 'local/no-casting-in-getFieldValueForRole': 'error' },
languageOptions: {
parser: tsParser,
ecmaVersion: 2015,
sourceType: 'module',
},
},
rules: {
'custom/no-casting-in-getFieldValueForRole': 'error',
},
languageOptions: { ecmaVersion: 2015, sourceType: 'module' },
});
]);
return messages;
};

Expand Down
Loading
Loading