dependabot[bot]
768f87bb1c
chore(deps): bump github.com/labstack/echo/v5 from 5.3.1 to 5.4.0
...
Bumps [github.com/labstack/echo/v5](https://github.com/labstack/echo ) from 5.3.1 to 5.4.0.
- [Release notes](https://github.com/labstack/echo/releases )
- [Changelog](https://github.com/labstack/echo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/labstack/echo/compare/v5.3.1...v5.4.0 )
---
updated-dependencies:
- dependency-name: github.com/labstack/echo/v5
dependency-version: 5.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-10-02 18:59:37 +02:00
dependabot[bot]
a5bc10b9d8
chore(deps-dev): bump prettier-plugin-sh from 0.19.0 to 0.20.2
...
Bumps [prettier-plugin-sh](https://github.com/un-ts/prettier ) from 0.19.0 to 0.20.2.
- [Release notes](https://github.com/un-ts/prettier/releases )
- [Changelog](https://github.com/un-ts/prettier/blob/master/CHANGELOG.md )
- [Commits](https://github.com/un-ts/prettier/compare/prettier-plugin-sh@0.19.0...prettier-plugin-sh@0.20.2 )
---
updated-dependencies:
- dependency-name: prettier-plugin-sh
dependency-version: 0.20.2
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-10-02 18:59:20 +02:00
dependabot[bot]
ffc3cb98af
chore(deps-dev): bump prettier from 3.9.8 to 3.9.9
...
Bumps [prettier](https://github.com/prettier/prettier ) from 3.9.8 to 3.9.9.
- [Release notes](https://github.com/prettier/prettier/releases )
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md )
- [Commits](https://github.com/prettier/prettier/compare/3.9.8...3.9.9 )
---
updated-dependencies:
- dependency-name: prettier
dependency-version: 3.9.9
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-10-02 18:59:08 +02:00
dependabot[bot]
8b46090eac
chore(deps-dev): bump prettier from 3.9.6 to 3.9.8
...
Bumps [prettier](https://github.com/prettier/prettier ) from 3.9.6 to 3.9.8.
- [Release notes](https://github.com/prettier/prettier/releases )
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md )
- [Commits](https://github.com/prettier/prettier/compare/3.9.6...3.9.8 )
---
updated-dependencies:
- dependency-name: prettier
dependency-version: 3.9.8
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-25 06:46:33 +02:00
dependabot[bot]
39e43205b1
chore(deps): bump golang.org/x/net from 0.58.0 to 0.59.0
...
Bumps [golang.org/x/net](https://github.com/golang/net ) from 0.58.0 to 0.59.0.
- [Commits](https://github.com/golang/net/compare/v0.58.0...v0.59.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-version: 0.59.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-18 09:27:35 +02:00
dependabot[bot]
c4c9ea12e5
chore(deps): bump golang.org/x/text from 0.41.0 to 0.42.0
...
Bumps [golang.org/x/text](https://github.com/golang/text ) from 0.41.0 to 0.42.0.
- [Release notes](https://github.com/golang/text/releases )
- [Commits](https://github.com/golang/text/compare/v0.41.0...v0.42.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/text
dependency-version: 0.42.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-18 07:02:04 +02:00
Julien Neuhart
ff817f6cf8
chore(deps)!: migrate from regexp2 v1 to regexp2 v2
2026-09-17 15:33:55 +02:00
Julien Neuhart
ab18384a51
build(dockerfile): update AWS Lambda Web Adapter to 1.0.1
2026-09-17 15:33:55 +02:00
Julien Neuhart
70783a01c6
fix(gotenberg): retry pattern matches aborted by a process pause
2026-09-16 21:23:43 +02:00
Julien Neuhart
2f9020455a
chore(deps)!: migrate from echo v4 to echo v5
2026-09-16 19:38:45 +02:00
Julien Neuhart
8e850b1c93
fix(outbound): ignore IPv6 zone identifiers when classifying addresses
2026-09-13 10:15:07 +02:00
Julien Neuhart
430ed38cc5
build(makefile): re-enable the embedlit go fix modernizer
v8.37.0
2026-09-11 16:13:06 +02:00
Julien Neuhart
623e93bf3e
chore(deps): update Go to 1.27.1
2026-09-11 16:13:06 +02:00
dependabot[bot]
fe4fb9416d
chore(deps): bump golang.org/x/sync from 0.22.0 to 0.23.0 ( #1658 )
...
Bumps [golang.org/x/sync](https://github.com/golang/sync ) from 0.22.0 to 0.23.0.
- [Commits](https://github.com/golang/sync/compare/v0.22.0...v0.23.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sync
dependency-version: 0.23.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-11 07:20:22 +02:00
Julien Neuhart
fb7536a526
fix(chromium): disable the WebUI omnibox popup preloaded at browser start
2026-09-09 19:38:40 +02:00
Julien Neuhart
b16ce08da7
perf(chromium): skip formatting a discarded debug message per response
2026-09-08 18:35:03 +02:00
Julien Neuhart
fcfd590169
perf(api): build the access log with a single record
2026-09-08 18:35:03 +02:00
Julien Neuhart
b39b8c76aa
perf(gotenberg): match allow and deny patterns without recompiling them
2026-09-08 18:34:58 +02:00
Julien Neuhart
06ed58b6e7
ci(build): reuse the Docker build cache across runs
2026-09-08 18:34:54 +02:00
Julien Neuhart
34b7b4845e
perf(pdfengines): process a request's files concurrently behind an opt-in ceiling
2026-09-08 18:34:51 +02:00
Julien Neuhart
ab3832d9e5
test(integration): drop the per-scenario Docker network
2026-09-08 18:34:43 +02:00
Julien Neuhart
cddaa0fa57
fix(chromium): ceiling the CONNECT tunnels in flight and bound tunnel writes
2026-09-07 18:13:29 +02:00
Julien Neuhart
ade6a327a4
fix(chromium): drop settled requests from the per-conversion network map
2026-09-07 18:13:29 +02:00
Julien Neuhart
35ddf81812
fix(libreoffice): stop the outbound proxy when the daemon fails to start
2026-09-07 18:13:29 +02:00
Julien Neuhart
1891a9ea68
fix(chromium): bound CONNECT tunnels so a silent upstream cannot pin them forever
2026-09-07 18:13:29 +02:00
Julien Neuhart
e1e0a80883
fix(webhook): close the response body when the callback returns an error status
2026-09-07 18:13:29 +02:00
Max Freedom Pollard
c21ceacd4b
fix(libreoffice): report an encrypted .xlsb as password-protected ( #1655 )
...
Uploading a password-protected .xlsb workbook without its password
answered 500 with the unattributable-failure message instead of 400 with
the remedy.
DetectPasswordProtection in pkg/modules/libreoffice/api/protection.go
infers encryption from a compound-file header carried by an extension
whose unencrypted form is always a ZIP package. The ooxmlExtensions map
listed .xlsx, .xlsm, .xltx and .xltm but not .xlsb, so an encrypted
workbook under that extension fell through to PasswordProtectionUnknown.
The convert route in pkg/modules/libreoffice/routes.go then matched
neither password branch of its exit-code switch and returned the 500
default.
An Excel Binary Workbook is an Open Packaging Conventions ZIP holding
binary parts, so a compound file under that extension is encrypted for
the same reason .xlsx is. Adding .xlsb to the map restores the 400 that
names the 'password' form field.
2026-09-06 13:05:20 +02:00
Julien Neuhart
ac825a2c03
feat(api): warn at startup when the debug route has no authentication
2026-09-05 14:04:21 +02:00
Julien Neuhart
2c9fa6b6ed
fix(exiftool): reject metadata keys that collide with ExifTool options
2026-09-05 14:04:21 +02:00
Julien Neuhart
ca8b45cd3a
fix(api): keep the filter verdict generic when a redirect is blocked
2026-09-05 14:04:21 +02:00
Julien Neuhart
40cf48442f
fix(outbound): treat CGNAT and benchmarking ranges as non-public
2026-09-05 11:34:03 +02:00
Julien Neuhart
df3bac99ed
fix(api): keep upload order when de-duplicating repeated filenames
2026-09-05 11:26:10 +02:00
Julien Neuhart
17868b8c02
fix(api): stop upload filenames from failing or silently dropping a request
2026-09-05 10:07:47 +02:00
Julien Neuhart
78284df590
fix(api): snapshot the output filename before echo recycles its context
2026-09-05 10:05:12 +02:00
Julien Neuhart
8f415186d5
fix(api): bound downloadFrom decoding by the entry limit
2026-09-05 10:03:56 +02:00
Julien Neuhart
f675f78f77
fix(webhook): bound webhook delivery with its own retry budget
2026-09-05 10:01:29 +02:00
Julien Neuhart
83b01c2baa
fix(api): bound downloadFrom requests by the request deadline
2026-09-05 09:59:29 +02:00
Julien Neuhart
9a46fdd681
style: escape backslashes in the Chromium allow-list scenario table
2026-09-04 20:00:22 +02:00
Julien Neuhart
4de9b0f68b
docs(outbound): document the allow-list bypass on every allow-list flag and terminate the example patterns
2026-09-04 19:55:57 +02:00
Julien Neuhart
201e80b9d7
feat(outbound): warn at startup about allow-list patterns that grant more than intended
2026-09-04 19:52:41 +02:00
Julien Neuhart
86a013b664
fix(outbound): strip URL userinfo before allow and deny list matching
2026-09-04 19:45:58 +02:00
Julien Neuhart
9c5acd7418
chore(deps): update Go dependencies
2026-09-04 10:00:28 +02:00
Julien Neuhart
e29b7cb4f5
build(makefile): fix lint-todo for golangci-lint v2
2026-09-03 19:23:14 +02:00
Julien Neuhart
23d59f3133
refactor: adopt strings.Cut and strings.SplitSeq
...
Applies what go fix now proposes, so make fmt is a no-op on a clean tree
instead of dirtying these two files on every run. Both rewrites are
equivalent: Cut's first result matches SplitN(s, sep, 2)[0], and SplitSeq
iterates the same substrings without building the intermediate slice.
2026-09-03 19:22:23 +02:00
Julien Neuhart
8a0de7d5d7
build(makefile): disable two go fix modernizers that emit broken code
...
go fix runs the modernize suite since Go 1.26, and two of its analyzers
rewrite this codebase into code that does not compile, so make fmt broke
the build and then make lint. CONTRIBUTING tells every contributor to run
both before opening a PR.
embedlit folded telemetryCfg.LogLevel into a literal that already set that
key, and errorsastype rewrote errors.As to errors.AsType[HttpError] even
though HttpError does not embed error. Disable both, with a TODO covering
when each can come back.
2026-09-03 19:22:23 +02:00
Julien Neuhart
3c691cbebc
test(health): assert conversions succeed across a planned restart
2026-09-03 17:55:35 +02:00
Julien Neuhart
0e83f737b4
docs(supervisor): point maybeRestartAfterTask at the timeout constant
2026-09-03 17:52:52 +02:00
Julien Neuhart
57b048c611
fix(supervisor): reset the request counter on a failed relaunch
...
restart() reset reqCounter only after a successful Launch, so a failed
one left it at the limit. maybeRestartAfterTask then re-fired on every
subsequent task, producing back-to-back restarts and, with planned
restarts now reporting healthy, a node that keeps restarting while
claiming health.
Reset on the attempt instead. A process that will not start is recovered
by ensureHealthy, which restarts synchronously and reports the failure.
2026-09-03 17:52:01 +02:00
Julien Neuhart
d79e174c6f
fix(supervisor): bound the eager restart with a deadline
...
maybeRestartAfterTask ran its restart on a bare background context while
the drain loop in doRestartLocked selects only on ctx.Done(). A task that
never completed blocked the drain forever, pinning isRestarting. Since a
planned restart now reports healthy, that left the node claiming health
for good. LibreOffice escaped it because its concurrency of 1 drains no
slots, but Chromium defaults to 6.
Give that restart its own deadline. On expiry it aborts and the next task
retries it.
2026-09-03 16:10:16 +02:00
Julien Neuhart
88ddaed09b
fix(supervisor): report healthy during planned process restarts
...
The eager restart fired after --chromium-restart-after or
--libreoffice-restart-after conversions made Healthy() report false,
so a client probing /health between two conversions got a 503 from an
otherwise serving node. Tasks arriving during that window are requeued
by acquireSlot, not rejected.
Track whether the in-flight restart is planned and keep reporting
healthy for those. Unplanned restarts still report unhealthy so load
balancers get honest information.
Closes #1648
2026-09-03 16:04:20 +02:00