Skip to content

fix(shelfmark): use built-in bypasser - #2893

Merged
MichielMak merged 2 commits into
mainfrom
fix/shelfmark-byparr-bypasser
Oct 4, 2026
Merged

MichielMak merged 2 commits into
mainfrom
fix/shelfmark-byparr-bypasser

Conversation

@MichielMak

@MichielMak MichielMak commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Why

Shelfmark searches on Anna's Archive kept failing.

  1. First, Shelfmark's default external bypasser URL is http://flaresolverr:8191, but no flaresolverr container exists here, so every request failed with Failed to resolve 'flaresolverr'.
  2. Pointing it at our byparr container fixed the connection, but byparr can't clear Anna's Archive's DDoS-Guard challenge (it returned the challenge page, marker /.well-known/ddos-guard/).
  3. Shelfmark's built-in SeleniumBase bypasser (included in the full image we run) does handle DDoS-Guard. With it enabled, searches work.

Change

Set USING_EXTERNAL_BYPASSER: false in shelfmark/compose.yaml.

Shelfmark copies env values into its config on every startup, so this overrides any UI change and keeps the working setup in git.

🤖 Generated with Claude Code

Shelfmark defaults EXT_BYPASSER_URL to http://flaresolverr:8191, which
doesn't exist in this setup. Pin it to the byparr container via env.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

🛡️ Trivy image scan — fixable HIGH/CRITICAL vulnerabilities found

The images below have known vulnerabilities with fixes available. Update to a patched image (digest) before merging.

ghcr.io/calibrain/shelfmark:v1.4.0@sha256:4ef757349c3c7a7d90ba95b1e2a46ce4dd460a4776efbcf2aa1b1c476e7d5de5

91 CRITICAL, 872 HIGH fixable vulnerabilities

CVE Package Installed Fixed Severity
CVE-2026-13221 perl-base 5.40.1-6 5.40.1-6+deb13u1 CRITICAL
CVE-2026-13775 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13775 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13776 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13776 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13780 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13780 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13781 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13781 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13782 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13782 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13785 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-13785 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14101 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14101 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14104 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14104 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14106 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14106 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14109 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14109 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14120 chromium 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-14120 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.46-1~deb13u1 CRITICAL
CVE-2026-15764 chromium 149.0.7827.196-1~deb13u1 150.0.7871.124-1~deb13u1 CRITICAL
CVE-2026-15764 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.124-1~deb13u1 CRITICAL
CVE-2026-15765 chromium 149.0.7827.196-1~deb13u1 150.0.7871.124-1~deb13u1 CRITICAL
CVE-2026-15765 chromium-common 149.0.7827.196-1~deb13u1 150.0.7871.124-1~deb13u1 CRITICAL
CVE-2026-17651 chromium 149.0.7827.196-1~deb13u1 151.0.7922.71-1~deb13u1 CRITICAL
CVE-2026-17651 chromium-common 149.0.7827.196-1~deb13u1 151.0.7922.71-1~deb13u1 CRITICAL
CVE-2026-17652 chromium 149.0.7827.196-1~deb13u1 151.0.7922.71-1~deb13u1 CRITICAL

…and 933 more. See the Actions log for the full report.

Byparr can't clear the DDoS-Guard challenge on Anna's Archive. The
built-in SeleniumBase bypasser can, so force external bypasser off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MichielMak MichielMak changed the title fix(shelfmark): point external bypasser at byparr fix(shelfmark): use built-in bypasser Oct 4, 2026
@MichielMak
MichielMak merged commit 9c67de7 into main Oct 4, 2026
2 of 3 checks passed
@MichielMak
MichielMak deleted the fix/shelfmark-byparr-bypasser branch October 4, 2026 20:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant