Skip to content

chore(deps-dev): bump @size-limit/file from 12.1.0 to 13.0.3 - #1952

Merged
LucasSantana-Dev merged 25 commits into
mainfrom
dependabot/npm_and_yarn/size-limit/file-13.0.3
Aug 14, 2026
Merged

LucasSantana-Dev merged 25 commits into
mainfrom
dependabot/npm_and_yarn/size-limit/file-13.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @size-limit/file from 12.1.0 to 13.0.3.

Release notes

Sourced from @​size-limit/file's releases.

13.0.3

  • Removed picocolors dependencies.

13.0.2

  • Fixed glob pattern regression.

13.0.1

  • Fixed publishing process.

13.0.0

  • Removed Node.js 20 support.
  • Removed tinyglobby and jiti dependencies.
  • Added npm provenance.
Changelog

Sourced from @​size-limit/file's changelog.

13.0.3

  • Removed picocolors dependencies.

13.0.2

  • Fixed glob pattern regression.

13.0.1

  • Fixed publishing process.

13.0.0

  • Removed Node.js 20 support.
  • Removed tinyglobby and jiti dependencies.
  • Added npm provenance.
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​size-limit/file since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 8, 2026
@socket-security

socket-security Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​size-limit/​file@​12.1.0 ⏵ 13.0.31001006791 +10100
Updated@​typescript-eslint/​parser@​8.66.0 ⏵ 8.67.0991007298100
Updated@​typescript-eslint/​eslint-plugin@​8.66.0 ⏵ 8.67.0991008098100
Updatedglobals@​17.9.0 ⏵ 17.10.010010086 +194 -1100
Updated@​testing-library/​user-event@​14.6.3 ⏵ 14.6.4100100100 +190100

View full report

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.


Graphify review — findings

This PR upgrades the @size-limit/file devDependency in packages/frontend from ^12.1.0 to ^13.0.3, updating both package.json and the corresponding entries in package-lock.json. The lockfile changes add a top-level size-limit 13.0.3 entry (peer) while pinning the frontend's nested size-limit at 12.1.0, and also drop several dev: true flags from optional @resvg/resvg-js platform binary packages.

Worth a look

  • Version mismatch between @size-limit/file and pinned size-limit — packages/frontend/package.json:70 · Escalate · high
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • size-limit version mismatch between @size-limit/file 13 and locked size-limit 12.1.0 — package-lock.json:27918 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

@LucasSantana-Dev

Copy link
Copy Markdown
Owner

Kimi review (kimi-code/kimi-for-coding, via local subscription)

• UserPromptSubmit hook

{
"hookSpecificOutput": {
"hookEventName": "UserPromptSubmit",
"additionalContext": "CAVEMAN ON (per CLAUDE.md): terse; drop filler/articles/hedging; keep ALL technical substance, exact terms, code + quoted errors verbatim; normal prose for security warnings, destructive-action confirmations, order-sensitive sequences. PONYTAIL FULL (per CLAUDE.md): ladder — YAGNI > reuse-what's-here > stdlib > native > installed dep > one line > minimal code; no unrequested abstractions; root-cause fix at shared fn; never trim trust-boundary validation/error handling/security; mark shortcuts 'ponytail:'. AGENT-ECON (standards/agent-routing.md): before any Agent()/swarm — recall/ctx_search first; cap reports ≤200 lines; grep-first briefs naming the ≤5 files worth full reads; thoroughness=medium default; index outputs >50KB via ctx_index then ctx_search, never Read-page them; resume failed agents, never respawn a swarm on quota 403."
}
}


Head a54fee4. Posted by kimi-review-watch (launchd).

Bumps [@size-limit/file](https://github.com/ai/size-limit) from 12.1.0 to 13.0.3.
- [Release notes](https://github.com/ai/size-limit/releases)
- [Changelog](https://github.com/ai/size-limit/blob/main/CHANGELOG.md)
- [Commits](ai/size-limit@12.1.0...13.0.3)

---
updated-dependencies:
- dependency-name: "@size-limit/file"
  dependency-version: 13.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/size-limit/file-13.0.3 branch from a54fee4 to f63c884 Compare August 10, 2026 18:35
@LucasSantana-Dev
LucasSantana-Dev enabled auto-merge (squash) August 11, 2026 23:13

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.


Graphify review — findings

This PR bumps the @size-limit/file dev dependency in packages/frontend/package.json from ^12.1.0 to ^13.0.3 and updates package-lock.json accordingly. The lockfile changes hoist size-limit@13.0.3 to the root (as a peer), pin the frontend package to size-limit@12.1.0 in its nested node_modules, and adjust several @resvg/resvg-js platform-specific binary entries to no longer be marked dev. The surface area is limited to dependency manifests and the lockfile; no application source code is touched.

Worth a look

  • size-limit peer dependency version mismatch with @size-limit/file 13.0.3 — packages/frontend/package.json:70 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • size-limit version mismatch between root (13.0.3) and frontend workspace (12.1.0) causes peerDependency conflict with @size-limit/file@13 — packages/frontend/package.json:70 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.


Graphify review — findings

This PR bumps the @size-limit/file dev dependency in packages/frontend from ^12.1.0 to ^13.0.3, updating both package.json and package-lock.json accordingly. The lockfile changes add a top-level size-limit 13.0.3 entry (with adjusted dependencies and Node engine requirements) while pinning the frontend package to a nested size-limit 12.1.0, and drop the dev: true flag from several optional @resvg/resvg-js platform binaries. The surface area is limited to dependency/lockfile metadata for the frontend package's bundle-size tooling.

Worth a look

  • size-limit version mismatch between @size-limit/file and hoisted size-limit — packages/frontend/package.json:70 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • @size-limit/file upgraded without matching size-limit CLI — packages/frontend/package.json:70 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 1 advisory finding(s) below merit a look before merge.


Graphify review — findings

This PR bumps the @size-limit/file devDependency in packages/frontend/package.json from ^12.1.0 to ^13.0.3. The package-lock.json is updated accordingly, adding a top-level size-limit 13.0.3 entry while pinning the frontend package to its own nested size-limit 12.1.0. The diff also touches various @resvg/resvg-js platform-specific optional dependency entries (removing their dev: true flags).

Worth a look

  • Version mismatch between @size-limit/file 13.x and size-limit 12.x peer requirement — packages/frontend/package.json:70 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

@github-actions github-actions Bot added size/xl and removed size/m labels Aug 12, 2026

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This PR updates package-lock.json and appears to touch packages/frontend/package.json dependency and script entries. The changes bump numerous transitive AWS SDK/Smithy package versions in the lockfile and adjust various frontend dependencies (e.g., Radix UI packages, i18next, tailwind-merge, clsx, zod), devDependencies (vitest, testing-library, jsdom, resvg), and script definitions (build, e2e tests, dependency security checks). This is primarily a dependency/lockfile maintenance change spanning the frontend package manifest and the repository-wide lockfile.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This PR updates package-lock.json, bumping the pinned versions of numerous transitive AWS SDK dependencies (e.g., @aws-sdk/core, @aws-sdk/credential-provider-*, @aws-sdk/nested-clients, @smithy/util-utf8) and adding a nested source-map entry under @apm-js-collab/code-transformer. The changed-symbols list also references various frontend package.json fields (dependencies, devDependencies, scripts, overrides), suggesting accompanying dependency/version metadata changes in the frontend package. This appears to be a routine dependency-update change touching lockfile and package manifest surface area.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This pull request updates the frontend package's dependency versions in package.json along with the corresponding entries in package-lock.json, touching packages such as React, react-hook-form, i18next, TanStack Query, Radix UI components, lucide-react, Vite/Vitest tooling, and various ESLint plugins. The diff also reflects transitive lockfile changes for AWS SDK and related sub-dependencies. The scope appears limited to dependency version bumps and associated script/config metadata, not application source logic.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

LucasSantana-Dev added a commit that referenced this pull request Aug 12, 2026
…race (#2003)

## Summary

- #1956 and #1952 hit \`Build — bot\`/\`Build — backend\` failing
repeatedly with \`failed to calculate checksum of ref ...:
"/app/packages/backend/node_modules": not found\` — immediately after
that exact stage completed successfully in the same build.
- Reproduced with the GHA docker cache fully emptied and the job run
alone (no concurrent PR builds), which rules out stale/cross-PR cache
corruption (see #2002).
- Points to BuildKit's own GC reclaiming a layer/blob still needed later
in the same multi-stage build, under disk pressure — \`ubuntu-latest\`
ships ~30GB of preinstalled toolchains (dotnet, GHC, Android SDK) this
Dockerfile never touches.

## Change

Adds a \`Free disk space\` step to
\`.github/actions/docker-build-service\` (used by the \`docker-build\`
matrix job in \`ci.yml\`) that removes the unused preinstalled
toolchains and prunes Docker's own unused layers before the build
starts.

## Test plan

- [ ] This PR's own \`Build — bot\`/\`Build — backend\`/\`Build — Docker
images\` checks pass (self-verifying)
- [ ] Once merged, #1956 and #1952 sync and their Docker builds pass
without the checksum error

<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Free up disk space on `ubuntu-latest` runners and prune Buildx builder
cache before Docker builds to prevent BuildKit GC from evicting needed
layers and causing intermittent checksum errors in bot/backend image
builds.

- **Bug Fixes**
- Add a “Free disk space” step to `.github/actions/docker-build-service`
before Buildx.
- Prune Buildx builder cache first (`docker buildx prune -af`), then
remove unused toolchains (dotnet, GHC, Android SDK, Swift, CodeQL), run
`docker system prune -af --volumes`, and print `df -h /`; cleanup
tolerates failures (`|| true`).
- Reduces disk pressure and stops the “checksum ... not found” errors
seen in #1956 and #1952.

<sup>Written for commit fdbb759.
Summary will update on new commits.</sup>

<a
href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2003?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>

<!-- End of auto-generated description by cubic. -->

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Improved container build reliability by freeing unused disk space
before image builds.
  * Added disk-space reporting to help monitor available capacity.
* Cleanup operations continue safely even if individual removal steps
fail.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This pull request updates package-lock.json, bumping the pinned versions of numerous transitive dependencies—primarily various @aws-sdk/* and @smithy/* packages—along with adding a nested source-map resolution under @apm-js-collab/code-transformer. Based on the changed-symbols list, it also touches the frontend package's dependency and devDependency entries (e.g. React, react-dom, tailwindcss, vitest, i18next, Sentry, Radix UI, and related scripts). The changes are confined to lockfile/manifest version metadata and dependency wiring rather than application source code.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This PR updates package-lock.json (and the associated packages/frontend/package.json dependency/devDependency/script entries referenced in the changed symbols). It bumps a range of dependency versions—including AWS SDK sub-packages, Smithy utilities, and frontend libraries such as TanStack React Query, Radix UI components, testing/tooling packages (Vitest, Playwright, Testing Library, ESLint plugins), and TypeScript/React type packages—and adds a nested source-map entry. The surface area is limited to dependency lockfile and package manifest changes rather than application source code.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This pull request updates dependencies for the frontend package. The package-lock.json changes bump various transitive AWS SDK and Smithy packages to newer patch versions, and the changed symbols indicate corresponding updates to the frontend package.json (dependencies like tailwind-merge, zod, axios, react-router-dom, Radix UI packages, and devDependencies like vitest, eslint, playwright, TypeScript ESLint plugins) along with related scripts, version, and size-limit configuration. The surface area is primarily dependency and lockfile maintenance affecting the frontend package's build, lint, and test tooling.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

LucasSantana-Dev added a commit that referenced this pull request Aug 14, 2026
…es (#2013)

## Problem

Retries in `.github/workflows/ci.yml`'s `docker-build` job already set
`use-cache: 'false'` to skip importing the gha layer cache after a
`failed to calculate checksum of ref ...: not found` failure — but
`cache-to` (mode=max export) stayed active regardless of `use-cache`.

## Evidence

PR #1956 and #1952 (2026-08-14) both exhausted all 3 attempts (build + 2
retries) with the identical error, even though retry 1 and retry 2 both
had `cache-from` disabled:

```
ERROR: failed to calculate checksum of ref ...: "/app/packages/backend/node_modules": not found
```

Cache import being off but the failure persisting identically means the
export side alone can trigger the same checksum-resolution failure —
`mode=max` has to solve a cache key for every intermediate stage,
including the branching `installed-deps` checkpoint that two downstream
stages (`source-copied` and `deps-production-base`) read from
concurrently.

## Fix

Gate `cache-to` by the same `use-cache` flag so retries run a genuinely
cache-free build (no import, no export) instead of only skipping import.

## Test plan

- [ ] This PR's own `docker-build` matrix job
(backend/bot/frontend/nginx) passes, validating the composite action
change works
- [ ] Once merged, rebase #1956 and #1952 onto main and confirm their
`Build — Docker images` required check goes green

<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Disable `cache-to` on `docker-build` retries when `use-cache` is false
to run a fully cache-free build and avoid the BuildKit “failed to
calculate checksum of ref …: not found” error. Previously, retries
disabled only `cache-from` while still exporting with `mode=max`, which
could reproduce the same failure during export.

- Change: In `.github/actions/docker-build-service/action.yml`, gate
`cache-to` by `inputs.use-cache` (mirrors `cache-from`). First attempts
unchanged; retries now skip both import and export.
- Validate: CI `docker-build` matrix should pass and show no cache
writes on retries.
- Follow-up: Rebase #1956 and #1952 and confirm `Build — Docker images`
passes.

<sup>Written for commit 33bdce6.
Summary will update on new commits.</sup>

<a
href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2013?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>

<!-- End of auto-generated description by cubic. -->



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved build caching behavior during retries and cache-resolution
failures.
* Cache export is now disabled when caching is turned off, preventing
unnecessary cache operations.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This pull request updates package-lock.json, bumping the versions of numerous transitive dependencies—primarily various @aws-sdk/* and @smithy/* packages—along with an added nested source-map resolution for @apm-js-collab/code-transformer. Based on the changed-symbols list, it also touches the frontend package's dependency and devDependency entries (e.g., React, Radix UI packages, Vite, TypeScript, ESLint, Tailwind, and related tooling). The changes are confined to dependency/lockfile metadata rather than application source code.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

LucasSantana-Dev added a commit that referenced this pull request Aug 14, 2026
)

## Context

Follow-up to #2013. That PR gated \`cache-to\` by \`use-cache\` on
retries so they run fully cache-free — this definitively ruled out the
gha cache as the cause (see #2002's latest comments): the identical
\`failed to calculate checksum of ref ...: not found\` error reproduced
6/6 across PR #1956 and #1952 with cache completely disabled.

Real cause is a local BuildKit race (filed as #2015) — not something to
fix with another CI-config tweak, needs a Dockerfile restructure.

## Interim mitigation

Since it's a race (not deterministic — some runs the same day
succeeded), bump retries from 2 to 4 (5 attempts total) to raise the
odds one attempt lands clean while #2015 is worked.

## Test plan

- [ ] This PR's own docker-build check passes

<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Increase CI docker-build retries from 2 to 4 (5 attempts total) to
mitigate a non-deterministic BuildKit race that triggers "failed to
calculate checksum of ref ...: not found". Previously we retried twice
with cache disabled on retries; now we retry four times, still disabling
cache on retries, trading longer worst-case time for higher pass rates
until the Dockerfile fix in issue #2015.

- Adds retry steps 2–4 and uses `continue-on-error: true` for the middle
attempts to allow progressing to the next retry; the final attempt
determines job failure.
- Leaves the first attempt unchanged and keeps `use-cache: 'false'` on
all retries.
- No other workflow logic changes; service-specific `load` behavior
remains the same.

<sup>Written for commit 1c267f7.
Summary will update on new commits.</sup>

<a
href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2016?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>

<!-- End of auto-generated description by cubic. -->

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This pull request updates package-lock.json, bumping the pinned versions of numerous transitive dependencies—primarily various @aws-sdk/* and @smithy/* packages—along with adding a nested source-map entry under @apm-js-collab/code-transformer. The changed symbol list also references many frontend package.json entries (e.g., React, Radix UI, Zustand, Playwright, ESLint tooling), suggesting frontend dependency metadata may be touched as well. The surface area is limited to dependency/lockfile management rather than application source code.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

LucasSantana-Dev added a commit that referenced this pull request Aug 14, 2026
Fixes the real root cause behind issue #2015 (and #2002): installed-deps
is concurrently extended by a second live branch (source-copied, via
FROM inheritance) for the rest of the build. deps-production-base's
three COPY --from=installed-deps steps were reading that stage while
it was still being written to elsewhere in the same build DAG, which
hit a BuildKit race resolving the cross-stage ref -- "failed to
calculate checksum of ref ...: not found" -- non-deterministically but
at a very high rate on GH Actions runners (10/10 recent attempts
across #1956 and #1952, even fully cache-free). Retries and cache
tuning (#2013, #2016) didn't fix it because it isn't a caching issue.

Running npm ci directly in deps-production-base (which already
branches straight from node:\${NODE_VERSION}, never touching
installed-deps or build) fully decouples this lineage: no more
cross-stage read of a stage still being concurrently written to. Cost
is one extra @discordjs/opus native compile, once per build (this
stage is shared by both deps-production-bot and deps-production-backend),
paid once instead of the 3-5 min routinely wasted on exhausted retries.

Not locally build-verified end-to-end: native C compilation under QEMU
cross-arch emulation (amd64 on this arm64 Mac, via colima) segfaults
GCC independent of this change (cc: internal compiler error:
Segmentation fault signal terminated program cc1) -- a known
QEMU/cross-compile instability class, not present on real amd64
hardware. Relying on CI (real amd64 runners) to validate.
LucasSantana-Dev added a commit that referenced this pull request Aug 14, 2026
## Root cause (issue #2015)

\`installed-deps\` (an empty checkpoint = \`FROM build AS
installed-deps\`) is consumed by two different lineages within a single
\`docker buildx build\` invocation for any \`production-*\` target:

1. \`source-copied\` (\`FROM installed-deps\`) → \`build-shared\` →
\`build-backend\`/\`build-bot\`/\`build-frontend\` — inherits and keeps
extending \`installed-deps\`'s filesystem with more COPY/RUN
instructions.
2. \`deps-production-base\` did \`COPY --from=installed-deps
/app/node_modules ...\` and \`COPY --from=installed-deps
/app/packages/shared/node_modules ...\`;
\`deps-production-bot\`/\`deps-production-backend\` each did one more
\`COPY --from=installed-deps\` for their own package's node_modules.

Both lineages read/extend \`installed-deps\` concurrently — BuildKit
parallelizes independent branches of the stage DAG by default. The
\`COPY --from\` reads in branch 2 race against branch 1 still actively
extending the same stage, and intermittently fail:

\`\`\`
ERROR: failed to calculate checksum of ref ...:
"/app/packages/backend/node_modules": not found
\`\`\`

Confirmed **not** a caching issue: reproduced 10/10 recent attempts
across #1956 and #1952 with the gha cache fully disabled (#2013), and
retries alone don't reliably dodge it even with 5 attempts (#2016).

## Fix

\`deps-production-base\` already branches straight from
\`node:${NODE_VERSION}\` (never touches \`installed-deps\` or
\`build\`). Give it its own \`npm ci\` instead of copying node_modules
out of \`installed-deps\` — this fully removes the cross-stage read of a
stage still being concurrently written to.
\`deps-production-bot\`/\`deps-production-backend\` no longer need any
\`COPY --from=installed-deps\` at all (npm workspaces already installs
every workspace's node_modules from the root \`npm ci\`).

Cost: one extra \`@discordjs/opus\` native compile, paid once per build
(this stage is shared by both bot and backend production targets) —
versus the 3-5 min routinely wasted on exhausted retries recently.

## Verification

Not locally build-verified end-to-end — native C compilation under QEMU
cross-arch emulation (amd64 on an arm64 Mac via colima) segfaults GCC
independent of this change (\`cc: internal compiler error: Segmentation
fault signal terminated program cc1\`), a known QEMU/cross-compile
instability class not present on real amd64 hardware. Relying on this
PR's own CI (real amd64 runners, matching production) to validate.

## Test plan

- [ ] This PR's own \`docker-build\` matrix (bot/backend/frontend/nginx)
passes, ideally on the very first attempt (no retries needed) — confirms
the race is actually gone, not just dodged
- [ ] \`Verify native modules load — bot\` step still passes (opus still
loads correctly from the independently-installed node_modules)
- [ ] Once merged, rebase #1956 and #1952 and confirm their Docker build
check goes green cleanly

<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Decouples `deps-production-base` from `installed-deps` by running `npm
ci` instead of copying `node_modules`. This removes a BuildKit race that
intermittently failed production builds with checksum-not-found errors.

- Replaces `COPY --from=installed-deps` with `npm ci` (with cache mount)
in `deps-production-base`; removes the per-package `COPY
--from=installed-deps` in `deps-production-bot` and
`deps-production-backend`; keeps `npm prune --omit=dev`.
- Fixes the root cause: `installed-deps` was read while another branch
still extended it, triggering parallel BuildKit races (“failed to
calculate checksum of ref …: not found”).
- Impact: one extra `@discordjs/opus` native compile once per build; no
runtime changes; workspace `npm ci` still installs all package
`node_modules`.
- Rollout: no migrations; CI should pass without retries. Rebase PRs
previously failing on issue #2015 after merge.

<sup>Written for commit 1b1a877.
Summary will update on new commits.</sup>

<a
href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2017?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>

<!-- End of auto-generated description by cubic. -->



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Improved production container dependency installation and caching.
  * Streamlined separate production builds for bot and backend services.
  * Reduced reliance on shared dependency copies between build stages.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This PR updates package-lock.json, bumping a large number of dependencies. It appears to cover patch/minor version bumps across AWS SDK packages (e.g. @aws-sdk/core, credential providers, nested clients) as well as frontend dependencies listed in the frontend package (React ecosystem, Radix UI components, Vite, Tailwind, testing libraries, Playwright, etc.). The surface area is limited to dependency version metadata and lockfile resolution rather than application source code.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

LucasSantana-Dev added a commit that referenced this pull request Aug 14, 2026
Even fully isolated (no concurrent PR builds, no cache at all), the
docker-build backend leg failed 5/5 attempts on both #1956 and #1952
with the same error the Dockerfile fix in #2017 partially addressed:

  failed to calculate checksum of ref ...: not found

That fix (decoupling deps-production-base from installed-deps)
validated clean once but didn't fully eliminate the race -- the same
signature reappeared on a different COPY --from step
(production-backend <- deps-production-backend), with the unrelated
build stage's own npm ci still running concurrently in the log at the
moment of failure. This is a BuildKit solver-level race under its
default concurrent stage scheduling, confirmed independent of caching
(#2013) and independent of cross-job/cross-PR concurrency (reproduces
running fully alone).

buildkitd-config-inline sets max-parallelism=1 on the ephemeral
docker-container builder, forcing one stage operation at a time.
Trades some build wall-clock for eliminating the race outright instead
of retrying around it.
LucasSantana-Dev added a commit that referenced this pull request Aug 14, 2026
…#2018)

## Context

Follow-up to #2017. That fix (decoupling `deps-production-base` from
`installed-deps`) validated clean once (4/4 services, attempt 1, no
retries) but didn't fully eliminate the race — rebuilding #1956 and
#1952 afterward, both failed 5/5 attempts again with the identical
error, now on a different `COPY --from` step (`production-backend`
reading `deps-production-backend`), with the `build` stage's own
unrelated `npm ci` still running concurrently in the log at the moment
of failure.

Ruled out as causes: gha cache (#2013 — fails identically fully
cache-free), cross-job/cross-PR concurrency (fails identically running
fully alone on an isolated rerun).

This is a BuildKit solver-level race under its default concurrent stage
scheduling — confirmed via Docker's own docs that `max-parallelism` is
exactly the documented knob for "particularly useful for low-powered
machines" style solver concurrency issues.

## Fix

`buildkitd-config-inline` on the `docker/setup-buildx-action` step sets
`max-parallelism = 1` (both `[worker.oci]` and `[worker.containerd]`,
covering whichever worker the image uses), forcing BuildKit to execute
one stage operation at a time instead of racing multiple branches
concurrently.

Trade-off: slower builds (no more parallel stage execution) in exchange
for actually eliminating the race instead of retrying around it. Can
tune back up (e.g. `max-parallelism = 2`) later if this proves too
conservative once we have clean data.

## Test plan

- [ ] This PR's own docker-build matrix passes on attempt 1 (no retries
needed) — the real signal that the race is gone
- [ ] Note build duration vs previous runs to gauge the serialization
cost

<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Serializes Docker BuildKit stage scheduling in CI and production
publishing to eliminate intermittent "failed to calculate checksum of
ref ...: not found" during COPY --from. Previously stages ran
concurrently; now both workflows set max-parallelism=1, trading some
build speed for reliability.

**Details**
- Configure `docker/setup-buildx-action` with `buildkitd-config-inline`
setting `[worker.oci]` and `[worker.containerd]` `max-parallelism = 1`
in `.github/actions/docker-build-service/action.yml` and
`.github/workflows/docker-publish.yml`.
- Update `.github/workflows/ci.yml` path filter to include
`.github/actions/docker-build-service/` so docker-build runs when its
composite action changes.
- Clarify Dockerfile header on reproducing vs suppressing the race; no
functional Dockerfile changes.

<sup>Written for commit 5c23bea.
Summary will update on new commits.</sup>

<a
href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/2018?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>

<!-- End of auto-generated description by cubic. -->

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved Docker image build reliability by serializing build stages,
helping prevent intermittent checksum-related failures.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This pull request updates package-lock.json with dependency version bumps. It advances numerous AWS SDK packages (e.g., @aws-sdk/core, @aws-sdk/nested-clients, various credential providers) to newer patch versions along with their transitive @smithy dependencies, and adds a nested source-map entry. The changed symbol list also references frontend package metadata (scripts, dependencies, and devDependencies such as vitest, tailwindcss, react-router-dom, and eslint tooling), suggesting related lockfile entries were touched as part of the same update.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

…rn/size-limit/file-13.0.3

# Conflicts:
#	package-lock.json
…it/file-13.0.3' into dependabot/npm_and_yarn/size-limit/file-13.0.3
@github-actions github-actions Bot added size/m and removed size/xl labels Aug 14, 2026
@LucasSantana-Dev
LucasSantana-Dev merged commit f117b20 into main Aug 14, 2026
27 of 29 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the dependabot/npm_and_yarn/size-limit/file-13.0.3 branch August 14, 2026 21:29

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

This PR bumps the @size-limit/file dev dependency in packages/frontend/package.json from ^12.1.0 to ^13.0.3, aligning it with the already-present size-limit@13.0.3. The package-lock.json is updated accordingly, adding the new nested @size-limit/file entry and removing the old top-level one, along with numerous incidental dev → devOptional reclassifications and optional-dependency metadata changes across unrelated packages.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 156 functions depend on the 156 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 156 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 156 function(s) in the blast radius were not formally verified this run

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file frontend javascript Pull requests that update javascript code size/m

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant