936bddf198
## Summary - Upgrades Node.js from 20.19.0 to 20.20.0 (and 22.12.0 to 22.22.0 for supervisor) to address the async_hooks stack overflow DoS vulnerability - Adds `maxDepth` parameter (default 128) to `flattenAttributes` and `unflattenAttributes` to prevent stack overflow on maliciously deep nested structures ## Details The vulnerability (patched in Node.js 20.20.0, 22.22.0, 24.13.0, 25.3.0) causes unrecoverable crashes (exit code 7) when stack overflow occurs during async_hooks callbacks. Since the webapp uses `AsyncLocalStorage`, it was theoretically vulnerable. ### Changes **Node.js version updates:** - `docker/Dockerfile`: 20.11.1 → 20.20.0 - `apps/supervisor/Containerfile`: 22-alpine → 22.22.0-alpine - `.nvmrc`: 20.19.0 → 20.20.0 - `apps/supervisor/.nvmrc`: 22.12.0 → 22.22.0 - `references/prisma-7/.nvmrc`: 20.19.0 → 20.20.0 - All GitHub workflows: 20.19.0 → 20.20.0 **Defense in depth:** - Added `maxDepth` parameter to `flattenAttributes()` and `unflattenAttributes()` in `packages/core` to prevent stack overflow on deeply nested user input ## Test plan - [x] All existing `flattenAttributes` tests pass (50 tests) - [x] New tests for depth limiting added - [x] Verify Docker builds work with new base images
69 lines
2.8 KiB
Markdown
69 lines
2.8 KiB
Markdown
# Guidance for Coding Agents
|
||
|
||
This repository is a pnpm monorepo managed with Turbo. It contains multiple apps and packages that make up the Trigger.dev platform and SDK.
|
||
|
||
## Repository layout
|
||
- `apps/webapp` – Remix application that serves as the main API and dashboard.
|
||
- `apps/supervisor` – Node application for executing built tasks.
|
||
- `packages/*` – Published packages such as `@trigger.dev/sdk`, the CLI (`trigger.dev`), and shared libraries.
|
||
- `internal-packages/*` – Internal-only packages used by the webapp and other apps.
|
||
- `references/*` – Example projects for manual testing and development of new features.
|
||
- `ai/references` – Contains additional documentation including an overview (`repo.md`) and testing guidelines (`tests.md`).
|
||
|
||
See `ai/references/repo.md` for a more complete explanation of the workspaces.
|
||
|
||
## Development setup
|
||
1. Install dependencies with `pnpm i` (pnpm `10.23.0` and Node.js `20.20.0` are required).
|
||
2. Copy `.env.example` to `.env` and generate a random 16 byte hex string for `ENCRYPTION_KEY` (`openssl rand -hex 16`). Update other secrets if needed.
|
||
3. Start the local services with Docker:
|
||
```bash
|
||
pnpm run docker
|
||
```
|
||
4. Run database migrations:
|
||
```bash
|
||
pnpm run db:migrate
|
||
```
|
||
5. Build the webapp, CLI and SDK packages:
|
||
```bash
|
||
pnpm run build --filter webapp && pnpm run build --filter trigger.dev && pnpm run build --filter @trigger.dev/sdk
|
||
```
|
||
6. Launch the development server:
|
||
```bash
|
||
pnpm run dev --filter webapp
|
||
```
|
||
The webapp runs on <http://localhost:3030>.
|
||
|
||
For full setup instructions see `CONTRIBUTING.md`.
|
||
|
||
## Running tests
|
||
- Unit tests use **vitest**. Run all tests:
|
||
```bash
|
||
pnpm run test
|
||
```
|
||
- Run tests for a specific workspace (example for `webapp`):
|
||
```bash
|
||
pnpm run test --filter webapp
|
||
```
|
||
- Prefer running a single test file from within its directory:
|
||
```bash
|
||
cd apps/webapp
|
||
pnpm run test ./src/components/Button.test.ts
|
||
```
|
||
If packages in that workspace need to be built first, run `pnpm run build --filter webapp`.
|
||
|
||
Refer to `ai/references/tests.md` for details on writing tests. Tests should avoid mocks or stubs and use the helpers from `@internal/testcontainers` when Redis or Postgres are needed.
|
||
|
||
## Coding style
|
||
- Formatting is enforced using Prettier. Run `pnpm run format` before committing.
|
||
- Follow the existing project conventions. Test files live beside the files under test and use descriptive `describe` and `it` blocks.
|
||
- Do not commit directly to the `main` branch. All changes should be made in a separate branch and go through a pull request.
|
||
|
||
## Additional docs
|
||
- The root `README.md` describes Trigger.dev and links to documentation.
|
||
- The `docs` workspace contains our documentation site, which can be run locally with:
|
||
```bash
|
||
pnpm run dev --filter docs
|
||
```
|
||
- `references/README.md` explains how to create new reference projects for manual testing.
|
||
|