Skip to content

chore(release): v2.1.6#315

Merged
Wootehfook merged 35 commits into
mainfrom
release/v2.1.6
Jul 17, 2026
Merged

chore(release): v2.1.6#315
Wootehfook merged 35 commits into
mainfrom
release/v2.1.6

Conversation

@Wootehfook

Copy link
Copy Markdown
Owner

Release v2.1.6

Cuts release v2.1.6 from develop into main. Merging this PR triggers create-release.yml to tag v2.1.6 and publish the GitHub Release from the CHANGELOG notes below.

Changed

Release checklist

  • Version bumped in package.json / package-lock.json2.1.6
  • CHANGELOG [2.1.6] section added with compare links
  • type-check, lint, and full test suite pass locally (117 tests)

🤖 Generated with Claude Code

Wootehfook and others added 30 commits May 25, 2026 19:47
Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
* fix: tighten watchlist comparison typing for sonar

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* fix: reduce explicit any usage in backend endpoints

* fix: align Error.cause typing with ES2022 target after runtime type refactor

---------

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Woo T. Fook <woot@users.noreply.github.com>
Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
* fix: tighten cache and friends runtime typings

* refactor: reuse shared D1 typings from cache in letterboxd friends

* fix: resolve TS2352 cast mismatch for D1 results

---------

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Woo T. Fook <woot@users.noreply.github.com>
* fix: reduce any usage in letterboxd compare and test endpoints

* fix: resolve TS2345 cast mismatch for D1 results in compare

---------

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Woo T. Fook <woot@users.noreply.github.com>
Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.0.10 to 8.0.14.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.0.14/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.0.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Woo T. Fook <221749694+Wootehfook@users.noreply.github.com>
…#281)

Bumps [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) from 8.59.4 to 8.60.0.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.60.0/packages/parser)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.60.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Woo T. Fook <221749694+Wootehfook@users.noreply.github.com>
Bumps [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) from 4.80.0 to 4.95.0.
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/HEAD/packages/wrangler)

---
updated-dependencies:
- dependency-name: wrangler
  dependency-version: 4.95.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Woo T. Fook <221749694+Wootehfook@users.noreply.github.com>
Bumps [lint-staged](https://github.com/lint-staged/lint-staged) from 16.3.0 to 17.0.7.
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v16.3.0...v17.0.7)

---
updated-dependencies:
- dependency-name: lint-staged
  dependency-version: 17.0.6
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Woo T. Fook <221749694+Wootehfook@users.noreply.github.com>
Bumps the npm_and_yarn group with 1 update in the / directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `vitest` from 4.0.18 to 4.1.0
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.0/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Admin-merged: automation infra PR, all checks green, blocked only on self-approval.
Admin-merged: manual conflict-resolution sync PR, all checks green, blocked only on self-approval. See PR body for conflict details (v2.1.5 -> develop).
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.1 to 26.1.1.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.9.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [eslint](https://github.com/eslint/eslint) from 10.2.1 to 10.7.0.
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.2.1...v10.7.0)

---
updated-dependencies:
- dependency-name: eslint
  dependency-version: 10.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [prettier](https://github.com/prettier/prettier) from 3.8.3 to 3.9.5.
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.3...3.9.5)

---
updated-dependencies:
- dependency-name: prettier
  dependency-version: 3.8.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.0.14 to 8.1.4.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.1.4/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.0.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) from 4.95.0 to 4.110.0.
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.110.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: wrangler
  dependency-version: 4.100.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…dates (#299)

Bumps the npm_and_yarn group with 1 update in the /workers/tmdb-cron directory: [esbuild](https://github.com/evanw/esbuild).


Updates `esbuild` from 0.27.3 to 0.28.1
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)
- [Commits](evanw/esbuild@v0.27.3...v0.28.1)

Updates `undici` from 7.24.4 to 7.28.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.24.4...v7.28.0)

Updates `esbuild` from 0.27.3 to 0.28.1
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)
- [Commits](evanw/esbuild@v0.27.3...v0.28.1)

Updates `undici` from 7.24.4 to 7.28.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.24.4...v7.28.0)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version: 0.28.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.28.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: esbuild
  dependency-version: 0.28.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.28.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Revise Dependabot auto-merge configuration

Updated auto-merge policy for Dependabot to include specific handling for major version bumps.

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…300)

Bumps [eslint-plugin-react-hooks](https://github.com/facebook/react/tree/HEAD/packages/eslint-plugin-react-hooks) from 7.0.1 to 7.1.1.
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/react/react/blob/main/packages/eslint-plugin-react-hooks/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/eslint-plugin-react-hooks@7.1.1/packages/eslint-plugin-react-hooks)

---
updated-dependencies:
- dependency-name: eslint-plugin-react-hooks
  dependency-version: 7.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.3/packages/plugin-react)

---
updated-dependencies:
- dependency-name: "@vitejs/plugin-react"
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.0 to 4.1.10.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Woo T. Fook <221749694+Wootehfook@users.noreply.github.com>
react and react-dom must stay on identical versions (React throws at
runtime otherwise). Dependabot was bumping them in separate PRs
(#301, #302), so each one landed with a version mismatch and failed
Test Suite / Backend Quality Checks. Grouping them makes Dependabot
open one PR with matching versions.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
---
updated-dependencies:
- dependency-name: react
  dependency-version: 19.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: react
- dependency-name: "@types/react"
  dependency-version: 19.2.17
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: react
- dependency-name: react-dom
  dependency-version: 19.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: react
- dependency-name: "@types/react"
  dependency-version: 19.2.17
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: react
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [jsdom](https://github.com/jsdom/jsdom) from 29.1.0 to 29.1.1.
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v29.1.0...v29.1.1)

---
updated-dependencies:
- dependency-name: jsdom
  dependency-version: 29.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) from 8.59.4 to 8.63.0.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.63.0/packages/eslint-plugin)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [lint-staged](https://github.com/lint-staged/lint-staged) from 17.0.7 to 17.0.8.
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.0.7...v17.0.8)

---
updated-dependencies:
- dependency-name: lint-staged
  dependency-version: 17.0.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot Bot and others added 4 commits July 13, 2026 01:25
…#311)

Bumps [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) from 8.60.0 to 8.63.0.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.63.0/packages/parser)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
TypeScript badge, Node engine requirement, and the friend-comparison
limit were stale against package.json and the actual code. Also
brings the User Guide in line with the real setup -> friend-selection
-> results flow instead of the old two-step description.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
…ools (#313)

* chore: Version bump to 2.1.5 and tooling / typing hygiene (#286)

* fix: harden common helper typings for sonar (#273)

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>

* fix: tighten watchlist comparison typing for sonar (#274)

* fix: tighten watchlist comparison typing for sonar

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* fix: reduce explicit any usage in backend endpoints (#275)

* fix: reduce explicit any usage in backend endpoints

* fix: align Error.cause typing with ES2022 target after runtime type refactor

---------

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Woo T. Fook <woot@users.noreply.github.com>

* fix: tighten ambient common module declarations (#276)

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>

* fix: tighten cache and friends runtime typings (#277)

* fix: tighten cache and friends runtime typings

* refactor: reuse shared D1 typings from cache in letterboxd friends

* fix: resolve TS2352 cast mismatch for D1 results

---------

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Woo T. Fook <woot@users.noreply.github.com>

* fix: reduce any usage in letterboxd compare and test endpoints (#278)

* fix: reduce any usage in letterboxd compare and test endpoints

* fix: resolve TS2345 cast mismatch for D1 results in compare

---------

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Woo T. Fook <woot@users.noreply.github.com>

* fix: tighten tmdb sync typing and db contracts (#279)

Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>

* chore(deps-dev): bump vite from 8.0.10 to 8.0.14 (#280)

Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.0.10 to 8.0.14.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.0.14/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.0.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Woo T. Fook <221749694+Wootehfook@users.noreply.github.com>

* chore(deps-dev): bump @typescript-eslint/parser from 8.59.4 to 8.60.0 (#281)

Bumps [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) from 8.59.4 to 8.60.0.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.60.0/packages/parser)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.60.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Woo T. Fook <221749694+Wootehfook@users.noreply.github.com>

* chore(deps-dev): bump wrangler from 4.80.0 to 4.95.0 (#283)

Bumps [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) from 4.80.0 to 4.95.0.
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/HEAD/packages/wrangler)

---
updated-dependencies:
- dependency-name: wrangler
  dependency-version: 4.95.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Woo T. Fook <221749694+Wootehfook@users.noreply.github.com>

* chore(deps-dev): bump lint-staged from 16.3.0 to 17.0.7 (#284)

Bumps [lint-staged](https://github.com/lint-staged/lint-staged) from 16.3.0 to 17.0.7.
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v16.3.0...v17.0.7)

---
updated-dependencies:
- dependency-name: lint-staged
  dependency-version: 17.0.6
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Woo T. Fook <221749694+Wootehfook@users.noreply.github.com>

* chore(deps-dev): bump vitest (#285)

Bumps the npm_and_yarn group with 1 update in the / directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `vitest` from 4.0.18 to 4.1.0
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.0/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: bump version to 2.1.5

* fix: address copilot review comments on PR 286

* fix: address PR 286 follow-up copilot review feedback

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Woo T. Fook <woot@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: GitHub Actions Bot - BoxdBuddies <github-actions@bodxdbud.io>

* chore: trim editor/devcontainer recommendations to project-relevant tools

Removes vendor-specific (GitHub Copilot) and stack-mismatched
(Tailwind, Makefile Tools, REST Client) extension recommendations,
plus an unused Python devcontainer feature, so cloning the repo only
prompts for tooling this codebase actually uses.

Also fixes .gitignore so .vscode/extensions.json (intentionally
tracked) can be re-staged by lint-staged without the ignored-path
warning that was failing the pre-commit hook.

* chore: ignore .claude/settings.local.json

Local Claude Code permission settings are machine-specific and
shouldn't be committed, same convention as other *.local.json files.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Wootehfook <wootehfook@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Woo T. Fook <woot@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: GitHub Actions Bot - BoxdBuddies <github-actions@bodxdbud.io>
Bump version to 2.1.6 and roll CHANGELOG. Includes PR #313 (editor/
devcontainer trim), PR #314 (README sync), backend TypeScript
type-hardening, release-sync automation, and dependency updates.
Copilot AI review requested due to automatic review settings July 17, 2026 22:37
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 17, 2026

Copy link
Copy Markdown

Deploying boxdbud with  Cloudflare Pages  Cloudflare Pages

Latest commit: 2b893c8
Status: ✅  Deploy successful!
Preview URL: https://6da45304.boxdbud.pages.dev
Branch Preview URL: https://release-v2-1-6.boxdbud.pages.dev

View logs

@sonarqubecloud

Copy link
Copy Markdown

@Wootehfook
Wootehfook merged commit 91daa74 into main Jul 17, 2026
34 checks passed
@Wootehfook
Wootehfook deleted the release/v2.1.6 branch July 17, 2026 22:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Release PR to cut v2.1.6 from develop into main, bundling documentation updates, dependency/tooling upgrades, tighter backend typings, and GitHub workflow automation/config tweaks.

Changes:

  • Bump project version to 2.1.6, update CHANGELOG/release notes, and refresh README (flow + prerequisites).
  • Upgrade dependencies/tooling (notably wrangler@4.110.0, TS target/lib to ES2022, React patch bumps) and tighten TS typings across Functions.
  • Update editor/devcontainer recommendations and add new GitHub Actions automation (main→develop sync + Dependabot auto-merge + Dependabot grouping).

Reviewed changes

Copilot reviewed 22 out of 25 changed files in this pull request and generated 8 comments.

Show a summary per file
File Description
workers/tmdb-cron/package.json Updates worker dev dependency wrangler (triggers related engine/peer constraints).
workers/tmdb-cron/package-lock.json Lockfile refresh for worker dependency graph following wrangler bump.
tsconfig.json Raises TS compile target/lib to ES2022.
README.md Syncs badges, prerequisites, and user flow steps with current app behavior.
package.json Bumps app version to 2.1.6, tightens Node engine requirement, updates dependencies/devDependencies.
functions/test/tmdb-check.ts Hardens handler typing (replaces any with structured env type).
functions/test/movie-search.ts Hardens handler typing (replaces any with structured env type).
functions/test/movie-lookup.ts Replaces any casts with typed row interfaces and safer logging env typing.
functions/search/index.ts Adds typed TMDB/D1 row shapes and removes any usage in query/result mapping.
functions/letterboxd/watchlist-count/index.ts Introduces D1 “like” types and typed .first<…>() result shape.
functions/letterboxd/friends/index.ts Improves typing around env/db/cache inputs; removes any logging/env casts.
functions/letterboxd/compare/index.ts Replaces any with unknown/typed row shapes; tightens logging/error serialization.
functions/letterboxd/cache/index.ts Defines D1-like interfaces and propagates stronger typing through cache helpers.
functions/letterboxd/avatar-proxy/index.ts Avoids any in env typing for MOVIES_DB.
functions/compare/index.ts Preserves scrape error cause and replaces any for TMDB row with a typed interface.
functions/api/watchlist-count-updates/index.ts Tightens payload validation types (unknown + structured narrowing).
functions/api/watchlist-comparison/index.ts Replaces any debug structures with explicit interfaces; improves D1 query typing.
functions/admin/tmdb-sync/index.ts Tightens TMDB/D1 typings, improves fetch timeout/error wrapping, reduces any.
functions/_types/common-modules.d.ts Improves ambient typings for shared helper module imports (reduces any).
functions/_types/ambient-common.d.ts Improves ambient typings for common helpers (KV/TMDB/debug/jsonResponse).
functions/_lib/common.d.ts Tightens helper type declarations (KV/TMDB/reduceMovie/debug/jsonResponse).
CHANGELOG.md Adds 2.1.6 section and updates compare links.
.vscode/extensions.json Trims extension recommendations to project-relevant tooling.
.gitignore Tracks .vscode/extensions.json while ignoring other .vscode/*; adds Claude local settings ignore.
.github/workflows/version-bump.yml Updates checkout pin; workflow still sets up Node 20.
.github/workflows/test-suite.yml Updates checkout action to v7; workflow still sets up Node 20.
.github/workflows/sync-main-to-develop.yml Adds new automation to cherry-pick release/hotfix merge into develop via PR.
.github/workflows/security.yml Updates checkout action to v7.
.github/workflows/security-supported-versions-check.yml Updates checkout action to v7; workflow still sets up Node 20.19.0.
.github/workflows/security-audit.yml Updates checkout action to v7.
.github/workflows/deploy-worker.yml Updates checkout action to v7; deploy workflow still sets up Node 20.
.github/workflows/dependabot-auto-merge.yml Adds new Dependabot auto-approve/auto-merge workflow.
.github/workflows/debug-pages-build.yml Updates checkout action to v7.
.github/workflows/create-release.yml Updates checkout action to v7.
.github/workflows/changelog-update.yml Skips changelog automation on sync PRs; updates checkout pin.
.github/workflows/build-application.yml Updates checkout action to v7; workflow still sets up Node 20.
.github/workflows/backend-quality-checks-resolver.yml Updates checkout action to v7; workflow still sets up Node 20.
.github/dependabot.yml Adds grouping so React/react-dom/@types bump together.
.github/copilot-instructions.md Documents auto-sync workflow + reinforces linear-history rules.
.devcontainer/devcontainer.json Removes unrelated devcontainer features/extensions; keeps stack-aligned tooling.
Files not reviewed (1)
  • workers/tmdb-cron/package-lock.json: Generated file
Comments suppressed due to low confidence (1)

.github/workflows/security-supported-versions-check.yml:20

  • This job is still explicitly pinned to Node 20.19.0, but the repo now requires Node >=22.22.1 (package.json engines) and wrangler@4.110.0 requires Node >=22. If this workflow is meant to validate supported versions, it should be updated to a supported Node version so it doesn’t fail immediately on installs or misrepresent the project’s runtime constraints.
      - uses: actions/checkout@v7
      - name: Use Node.js 20.19.0
        uses: actions/setup-node@v6
        with:
          node-version: "20.19.0"

@@ -0,0 +1,58 @@
# AI Generated: Claude (Cowork) - 2026-07-12
Comment on lines 17 to 21
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: Setup Node.js
uses: actions/setup-node@v6
Comment on lines 16 to 20
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: Setup Node.js
uses: actions/setup-node@v6
Comment on lines 17 to 21
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: Setup Node.js
uses: actions/setup-node@v6
Comment on lines 27 to 31
- name: Checkout
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: Use Node.js
uses: actions/setup-node@v6
Comment on lines 37 to 41
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
with:
fetch-depth: 0
token: ${{ env.RELEASE_PR_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6
with:
node-version: "20"
Comment on lines 12 to +15
"devDependencies": {
"@cloudflare/workers-types": "^4.20250101.0",
"typescript": "^5.9.3",
"wrangler": "^4.80.0"
"wrangler": "^4.110.0"
Copilot AI review requested due to automatic review settings July 17, 2026 22:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 22 out of 25 changed files in this pull request and generated 2 comments.

Files not reviewed (1)
  • workers/tmdb-cron/package-lock.json: Generated file
Comments suppressed due to low confidence (10)

.github/workflows/test-suite.yml:21

  • This workflow uses Node 20, but the repo now declares an engine requirement of Node >=22.22.1. Keeping Node 20 here risks failing installs/build/tests (and newer tooling like wrangler also requires Node 22+). Update the setup-node version to match the repo’s declared minimum.
      - name: Checkout repository
        uses: actions/checkout@v7

      - name: Setup Node.js
        uses: actions/setup-node@v6

.github/workflows/security-audit.yml:30

  • This job runs npm ci under Node 20.19.0, but the repository declares Node >=22.22.1 in package.json engines. Update the CI Node version to the minimum supported version to avoid install/runtime issues.
      - uses: actions/checkout@v7

      - name: Setup Node.js
        uses: actions/setup-node@v6
        with:

.github/workflows/build-application.yml:20

  • This build job uses Node 20, but the repo requires Node >=22.22.1 (package.json engines). Using an older Node risks failing installs/builds as dependencies update. Please bump the setup-node version accordingly.
      - name: Checkout repository
        uses: actions/checkout@v7

      - name: Setup Node.js
        uses: actions/setup-node@v6

.github/workflows/version-bump.yml:41

  • This workflow runs npm commands with Node 20, but the repository’s engines require Node >=22.22.1. Updating the Node version here will prevent engine/tooling mismatches during version bumps and release automation.
      - name: Checkout repository
        uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6
        with:
          fetch-depth: 0
          token: ${{ env.RELEASE_PR_TOKEN }}

.github/workflows/deploy-worker.yml:21

  • The worker deploy job uses Node 20, but the worker’s updated wrangler dependency requires Node >=22.0.0 (and the main repo engines require >=22.22.1). Update setup-node to avoid wrangler/tooling failures during deploy.
            - name: Checkout repository
              uses: actions/checkout@v7

            - name: Setup Node.js
              uses: actions/setup-node@v6

.github/workflows/backend-quality-checks-resolver.yml:31

  • This workflow installs and runs the project under Node 20, but the repo declares Node >=22.22.1 in package.json engines. Update setup-node to the supported minimum to keep the required check stable.
      - name: Checkout
        uses: actions/checkout@v7

      - name: Use Node.js
        uses: actions/setup-node@v6

.github/workflows/sync-main-to-develop.yml:59

  • This new sync workflow runs npm ci/lint/test/build under Node 20, but the repository requires Node >=22.22.1 (package.json engines). Using Node 20 here risks the sync PR failing verification and never being opened/auto-merged.
      - name: Setup Node.js
        uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6
        with:
          node-version: "20"
          cache: "npm"

.github/workflows/security-supported-versions-check.yml:20

  • This workflow step name and configured Node version still reference 20.19.0, but the repository’s declared minimum is Node >=22.22.1. Updating this keeps the “supported versions” checks aligned with the project’s actual support policy.
      - uses: actions/checkout@v7
      - name: Use Node.js 20.19.0
        uses: actions/setup-node@v6
        with:
          node-version: "20.19.0"

.github/workflows/dependabot-auto-merge.yml:1

  • Repo policy requires AI-generated files to start with an attribution header in the form “AI Generated: GitHub Copilot () - YYYY-MM-DD” (see .github/copilot-instructions.md). This file’s header doesn’t follow that required format.
# AI Generated: Claude (Cowork) - 2026-07-12

workers/tmdb-cron/package.json:15

  • wrangler@4.110.0 declares a peer dependency on @cloudflare/workers-types ^5.20260708.1 (see workers/tmdb-cron/package-lock.json). The worker package.json still pins @cloudflare/workers-types to a v4 range, which can cause type/package resolution drift. Consider bumping workers-types to match wrangler’s peer dependency.
  "devDependencies": {
    "@cloudflare/workers-types": "^4.20250101.0",
    "typescript": "^5.9.3",
    "wrangler": "^4.110.0"

Comment on lines 31 to 35
- name: Checkout code
uses: actions/checkout@v6
uses: actions/checkout@v7
with:
fetch-depth: 0

Comment on lines 20 to 24
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: Setup Node.js
uses: actions/setup-node@v6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants